X.Org
cpe:2.3:a:x.org:xorg-server:*:*:*:*:*:*:*, +2 more
- <= 21.1.15
A use-after-free vulnerability has been identified in X.Org and Xwayland. This flaw occurs when a device is removed while still frozen, leaving queued events for the device intact even after it has been freed. Replaying these events can trigger the use-after-free condition.
Exploitation of this vulnerability leads to a use-after-free condition, which can cause memory corruption. This type of vulnerability may be exploited to execute arbitrary code or commands, potentially allowing for privilege escalation.
Users can apply the available update for this vulnerability. Instructions for applying the update can be found in the Red Hat Product Errata RHSA-2025:7163, RHSA-2025:7165, and RHSA-2025:7458.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.