News: 0001587528

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Three More X.Org Server & XWayland Security Vulnerabilities Made Public

([X.Org] 3 Hours Ago X.Org Server)


The Trend Micro Zero Day Initiative has uncovered three more security vulnerabilities affecting the X.Org Server and the derived XWayland source code.

Olivier Fourdan announced publicly today the newest X.Org Server and XWayland security vulnerabilities uncovered by the Trend Micro Zero Day Initiative. In turn xorg-server 21.1.19 and XWayland 24.1.9 were released as the newest point releases for addressing these security issues.

These newest security vulnerabilities to the X.Org Server include:

CVE-2025-62229: Use-after-free in XPresentNotify structures creation

CVE-2025-62230: Use-after-free in Xkb client resource removal

CVE-2025-62231: Value overflow in Xkb extension XkbSetCompatMap()

The latter two have been in the X.Org codebase going back to X11R6 while the first one has been present since X.Org Server 1.15. X11R6 first released back in 1994.

More details on these latest security issues can be found via the [1]X.Org announcement .



[1] https://lists.x.org/archives/xorg-announce/2025-October/003635.html



ROMEO: Courage, man; the hurt cannot be much.
MERCUTIO: No, 'tis not so deep as a well, nor so wide
as a church-door; but 'tis enough, 'twill serve.