Impact
The flaw arises from an integer truncation during memory allocation in the XKB component of the Xorg X11 server. Because the truncation causes the server to allocate a buffer that is smaller than required when resizing key types, an authenticated local client can send crafted XKB requests that overflow the heap. The overflow can be used to execute arbitrary code on the host or to crash the X server, enabling denial of service or local privilege escalation in the worst case.
Affected Systems
The vulnerability affects the xorg-x11-server binary. Supported versions are not listed, but any installation containing the vulnerable XKB extension may be impacted. The flaw can be triggered by a locally authenticated client that communicates with the X server on the same machine.
Risk and Exploitability
The CVSS score of 7.8 signals a high risk level. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. Because the attack requires a local authenticated client, widespread exploitation is limited compared to remote attacks, but an attacker who gains local access can exploit the heap overflow to achieve arbitrary code execution or crash the X server, causing service disruption. Defensive actions include applying extension until a fix is released.
OpenCVE Enrichment