News: 0001587528

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Three More X.Org Server & XWayland Security Vulnerabilities Made Public

([X.Org] 3 Hours Ago X.Org Server)


The Trend Micro Zero Day Initiative has uncovered three more security vulnerabilities affecting the X.Org Server and the derived XWayland source code.

Olivier Fourdan announced publicly today the newest X.Org Server and XWayland security vulnerabilities uncovered by the Trend Micro Zero Day Initiative. In turn xorg-server 21.1.19 and XWayland 24.1.9 were released as the newest point releases for addressing these security issues.

These newest security vulnerabilities to the X.Org Server include:

CVE-2025-62229: Use-after-free in XPresentNotify structures creation

CVE-2025-62230: Use-after-free in Xkb client resource removal

CVE-2025-62231: Value overflow in Xkb extension XkbSetCompatMap()

The latter two have been in the X.Org codebase going back to X11R6 while the first one has been present since X.Org Server 1.15. X11R6 first released back in 1994.

More details on these latest security issues can be found via the [1]X.Org announcement .



[1] https://lists.x.org/archives/xorg-announce/2025-October/003635.html



I am approached with the most opposite opinions and advice, and by men who
are equally certain that they represent the divine will. I am sure that
either the one or the other is mistaken in the belief, and perhaps in some
respects, both.

I hope it will not be irreverent of me to say that if it is probable that
God would reveal his will to others on a point so connected with my duty,
it might be supposed he would reveal it directly to me.
-- Abraham Lincoln