Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 43: Critical NULL Pointer Dereference Vulnerability in xkbcomp

fedora
Calendar Grey December 6, 2025
Dist Fedora Esm H88
Critical update for Fedora 43 addressing multiple xkbcomp crashes from NULL pointer dereferences and other keymap issues.
xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863)

Summary

X.Org XKB keymap compiler

Update Information:

xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863)

Change Log

* Wed Dec 3 2025 Peter Hutterer - 1.5.0-1 - xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863)

References


[ 1 ] Bug #2418046 - CVE-2018-15853 xkbcomp: Endless recursion in xkbcomp/expr.c resulting in a crash [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2418046 [ 2 ] Bug #2418048 - CVE-2018-15863 xkbcomp: NULL pointer dereference in ResolveStateAndPredicate resulting in a crash [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2418048 [ 3 ] Bug #2418050 - CVE-2018-15861 xkbcomp: NULL pointer dereference in ExprResolveLhs resulting in a crash [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2418050 [ 4 ] Bug #2418053 - CVE-2018-15859 xkbcomp: NULL pointer dereference when parsing invalid atoms in ExprResolveLhs resulting in a crash [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2418053

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3a9b79ca0e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: xkbcomp
Product: Fedora 43
Version: 1.5.0
Release: 1.fc43
Summary: XKB keymap compiler

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here