Intel

AIKIDO-2025-10605

xcb is vulnerable to Operation on a Resource after Expiration or Release

Operation on a Resource after Expiration or ReleaseGHSA-655h-hg88-5qmf Published Sep 2, 2025

63

Medium Risk

This Affects:

RUSTxcb
0.4.0 - 1.5.0
Fixed in 1.6.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Operation on a Resource after Expiration or Release in the Connection::connect_with_fd and Connection::connect_with_fd_and_extensions functions. By supplying a crafted RawFd, an attacker can trigger unintended closure of file descriptors, potentially leading to use-after-close conditions, resource mismanagement, or denial of service through repeated closure of already-closed descriptors.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

xcb is vulnerable to Operation on a Resource after Expiration or Release in versions 0.4.0 - 1.5.0.

How to fix this

Upgrade the xcb library to the patch version.