CVE-2025-62231 | Xorg: xmayland: value overflow in xkbsetcompatmap()

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.

Published: 2025-10-30 Last update: 2026-04-20 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2025-62231 is rated Low Risk (30/100): CVSS High severity, with low exploitation likelihood (EPSS 0.01%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2025-62231

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-10-30 0.01%

Full EPSS history (1 record total)

Common vulnerability scoring system (CVSS) metrics for CVE-2025-62231

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.3 3.1 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.8 5.5 [email protected]

Weakness enumeration for CVE-2025-62231

GitHub Security Advisory for CVE-2025-62231

GHSA-h4r4-6hvf-34r8 · Severity: high — A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds...

OS Trackers for CVE-2025-62231

vendor priority summary link
alpine CVE-2025-62231: 2 source package rows (xorg-server, xwayland); 5 state rows across 3 repos (3.22-community, 3.23-community, edge-community); fixed 5, open 0. https://security.alpinelinux.org/vuln/CVE-2025-62231
debian not yet assigned CVE-2025-62231 not yet assigned priority: Debian including 2 source packages (xorg-server, xwayland), 9 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 7, open 2. https://security-tracker.debian.org/tracker/CVE-2025-62231
redhat medium https://access.redhat.com/security/cve/CVE-2025-62231
suse high https://www.suse.com/security/cve/CVE-2025-62231/
ubuntu medium CVE-2025-62231 medium priority: Ubuntu including 7 source packages (xorg, xorg-hwe-16.04, …), 46 status rows across 9 suites (bionic, focal, jammy, noble, plucky, questing, trusty, upstream, xenial): DNE 16, not-affected 12, released 10, needs-triage 8. https://ubuntu.com/security/CVE-2025-62231

Affected software / configurations for CVE-2025-62231

Vendor Product Version Raw CPE
No affected products in dataset.

References for CVE-2025-62231

URL Tags
https://access.redhat.com/errata/RHSA-2025:19432
https://access.redhat.com/errata/RHSA-2025:19433
https://access.redhat.com/errata/RHSA-2025:19434
https://access.redhat.com/errata/RHSA-2025:19435
https://access.redhat.com/errata/RHSA-2025:19489
https://access.redhat.com/errata/RHSA-2025:19623
https://access.redhat.com/errata/RHSA-2025:19909
https://access.redhat.com/errata/RHSA-2025:20958
https://access.redhat.com/errata/RHSA-2025:20960
https://access.redhat.com/errata/RHSA-2025:20961
https://access.redhat.com/errata/RHSA-2025:21035
https://access.redhat.com/errata/RHSA-2025:22040
https://access.redhat.com/errata/RHSA-2025:22041
https://access.redhat.com/errata/RHSA-2025:22051
https://access.redhat.com/errata/RHSA-2025:22055
https://access.redhat.com/errata/RHSA-2025:22056
https://access.redhat.com/errata/RHSA-2025:22077
https://access.redhat.com/errata/RHSA-2025:22096
https://access.redhat.com/errata/RHSA-2025:22164
https://access.redhat.com/errata/RHSA-2025:22167
https://access.redhat.com/errata/RHSA-2025:22364
https://access.redhat.com/errata/RHSA-2025:22365
https://access.redhat.com/errata/RHSA-2025:22426
https://access.redhat.com/errata/RHSA-2025:22427
https://access.redhat.com/errata/RHSA-2025:22667
https://access.redhat.com/errata/RHSA-2025:22729
https://access.redhat.com/errata/RHSA-2025:22742
https://access.redhat.com/errata/RHSA-2025:22753
https://access.redhat.com/errata/RHSA-2026:0031
https://access.redhat.com/errata/RHSA-2026:0033
https://access.redhat.com/errata/RHSA-2026:0034
https://access.redhat.com/errata/RHSA-2026:0035
https://access.redhat.com/errata/RHSA-2026:0036
https://access.redhat.com/security/cve/CVE-2025-62231
https://bugzilla.redhat.com/show_bug.cgi?id=2402660
https://lists.x.org/archives/xorg-announce/2025-October/003635.html
http://www.openwall.com/lists/oss-security/2025/10/28/7
https://lists.debian.org/debian-lts-announce/2025/10/msg00033.html
cvelogic Threat Intelligence