Bug 2402660 (CVE-2025-62231)

Summary: CVE-2025-62231 xorg: xmayland: Value overflow in XkbSetCompatMap()
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2406802, 2406803, 2407295, 2407296, 2407297    
Bug Blocks:    
Deadline: 2025-10-28   

Description OSIDB Bzimport 2025-10-09 06:46:27 UTC
Integer overflow vulnerability in the XkbSetCompatMap() function of the X.Org X server and Xwayland. The XkbCompatMap structure uses unsigned short values for some fields but fails to verify that input sums do not exceed the valid range. Crafted XkbSetCompatMap requests can trigger arithmetic overflow, potentially corrupting memory and causing the X server to crash.

Comment 1 errata-xmlrpc 2025-11-03 08:43:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:19435 https://access.redhat.com/errata/RHSA-2025:19435

Comment 2 errata-xmlrpc 2025-11-03 08:44:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:19432 https://access.redhat.com/errata/RHSA-2025:19432

Comment 3 errata-xmlrpc 2025-11-03 08:54:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:19433 https://access.redhat.com/errata/RHSA-2025:19433

Comment 4 errata-xmlrpc 2025-11-03 09:00:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:19434 https://access.redhat.com/errata/RHSA-2025:19434

Comment 5 errata-xmlrpc 2025-11-03 15:43:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:19489 https://access.redhat.com/errata/RHSA-2025:19489

Comment 6 errata-xmlrpc 2025-11-04 10:21:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:19623 https://access.redhat.com/errata/RHSA-2025:19623

Comment 8 errata-xmlrpc 2025-11-06 13:01:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:19909 https://access.redhat.com/errata/RHSA-2025:19909

Comment 9 errata-xmlrpc 2025-11-11 15:00:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:20958 https://access.redhat.com/errata/RHSA-2025:20958

Comment 10 errata-xmlrpc 2025-11-11 15:01:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:20961 https://access.redhat.com/errata/RHSA-2025:20961

Comment 11 errata-xmlrpc 2025-11-11 15:01:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:20960 https://access.redhat.com/errata/RHSA-2025:20960

Comment 12 errata-xmlrpc 2025-11-11 19:49:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:21035 https://access.redhat.com/errata/RHSA-2025:21035

Comment 13 errata-xmlrpc 2025-11-25 07:49:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:22041 https://access.redhat.com/errata/RHSA-2025:22041

Comment 14 errata-xmlrpc 2025-11-25 07:50:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:22040 https://access.redhat.com/errata/RHSA-2025:22040

Comment 15 errata-xmlrpc 2025-11-25 08:20:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:22056 https://access.redhat.com/errata/RHSA-2025:22056

Comment 16 errata-xmlrpc 2025-11-25 08:26:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:22055 https://access.redhat.com/errata/RHSA-2025:22055

Comment 17 errata-xmlrpc 2025-11-25 08:33:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:22051 https://access.redhat.com/errata/RHSA-2025:22051

Comment 18 errata-xmlrpc 2025-11-25 13:01:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:22077 https://access.redhat.com/errata/RHSA-2025:22077

Comment 19 errata-xmlrpc 2025-11-25 17:19:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:22096 https://access.redhat.com/errata/RHSA-2025:22096

Comment 20 errata-xmlrpc 2025-11-26 05:23:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:22164 https://access.redhat.com/errata/RHSA-2025:22164

Comment 21 errata-xmlrpc 2025-11-26 07:13:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2025:22167 https://access.redhat.com/errata/RHSA-2025:22167

Comment 22 errata-xmlrpc 2025-12-01 01:57:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:22365 https://access.redhat.com/errata/RHSA-2025:22365

Comment 23 errata-xmlrpc 2025-12-01 02:37:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:22364 https://access.redhat.com/errata/RHSA-2025:22364

Comment 24 errata-xmlrpc 2025-12-01 14:34:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:22427 https://access.redhat.com/errata/RHSA-2025:22427

Comment 25 errata-xmlrpc 2025-12-01 14:37:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:22426 https://access.redhat.com/errata/RHSA-2025:22426

Comment 26 errata-xmlrpc 2025-12-03 14:24:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION

Via RHSA-2025:22667 https://access.redhat.com/errata/RHSA-2025:22667

Comment 27 errata-xmlrpc 2025-12-04 07:38:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:22729 https://access.redhat.com/errata/RHSA-2025:22729

Comment 28 errata-xmlrpc 2025-12-04 10:17:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:22742 https://access.redhat.com/errata/RHSA-2025:22742

Comment 29 errata-xmlrpc 2025-12-04 12:48:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2025:22753 https://access.redhat.com/errata/RHSA-2025:22753

Comment 30 errata-xmlrpc 2026-01-05 06:02:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:0031 https://access.redhat.com/errata/RHSA-2026:0031

Comment 31 errata-xmlrpc 2026-01-05 06:08:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2026:0034 https://access.redhat.com/errata/RHSA-2026:0034

Comment 32 errata-xmlrpc 2026-01-05 06:12:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:0036 https://access.redhat.com/errata/RHSA-2026:0036

Comment 33 errata-xmlrpc 2026-01-05 06:14:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2026:0035 https://access.redhat.com/errata/RHSA-2026:0035

Comment 34 errata-xmlrpc 2026-01-05 06:14:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:0033 https://access.redhat.com/errata/RHSA-2026:0033