Logo
vulnerabilityCVE-2025-62229
Name
CVE-2025-62229
Source
NVD ( link)Debian ( link)
Description
A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
xserver-xorg
Patched
xwayland
Patched

Vulnerability Ratings#


7.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
24.1.12
Not Affected
buildroot
master
24.1.12
Not Affected
yocto
master
21.1.23
Not Affected
yocto
master
24.1.12
Not Affected
yocto
scarthgap
21.1.18
Patched
yocto
scarthgap
23.2.5
Patched

Resolved with patches#


xserver-xorg (yocto:kirkstone)

#
Title
Author
Resolve
1
present: Fix use-after-free in present_create_notifies()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-62229

xwayland (yocto:kirkstone)

#
Title
Author
Resolve
1
present: Fix use-after-free in present_create_notifies()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-62229

xserver-xorg (yocto:scarthgap)

#
Title
Author
Resolve
1
present: Fix use-after-free in present_create_notifies()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-62229

xwayland (yocto:scarthgap)

#
Title
Author
Resolve
1
present: Fix use-after-free in present_create_notifies()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2025-62229