Executive brief
A vulnerability was found in the X.Org X server, a fundamental component used to manage graphical displays and user input on Linux and Unix-like systems. An attacker with local access to a system could send specially crafted keyboard configuration data to trigger a memory error. This could allow the attacker to crash the display system or potentially gain unauthorized access to sensitive information or elevated privileges on the machine.
Technical details
An integer overflow vulnerability exists in the XkbSetCompatMap() function within the X Keyboard (Xkb) extension of the X.Org X server. The flaw is caused by improper bounds checking when processing input data, leading to an unsigned short overflow during value calculation. A local attacker can exploit this by sending specially crafted requests to the X server, resulting in memory corruption or a denial-of-service (crash). Depending on the memory layout, this could potentially lead to local privilege escalation. Patches have been released by X.Org and major Linux distributions like Red Hat and Debian.
Affected products
- X.Org X server versions before 21.1.14 and 1.20.11-32.el9_6
- X.Org Xwayland versions before 24.1.9
- Red Hat Red Hat Enterprise Linux 8 xorg-x11-server-Xwayland < 21.1.3-19.el8_10
- Red Hat Red Hat Enterprise Linux 9 xorg-x11-server < 1.20.11-32.el9_6
Timeline
- 2025-10-28: disclosed: Public disclosure on oss-security mailing list
- 2025-10-30: advisory: NVD publication date
- 2025-11-03: patched: Red Hat released security updates (RHSA-2025:19432, RHSA-2025:19433)
References
- https://gitlab.freedesktop.org/xorg/xserver
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2025:19432
- https://access.redhat.com/errata/RHSA-2025:19433
- https://access.redhat.com/errata/RHSA-2025:19434
- https://access.redhat.com/errata/RHSA-2025:19435
- https://access.redhat.com/errata/RHSA-2025:19489