Description
A flaw was found in xorg-x11-server. The server writes pointer barrier events into a fixed-size buffer without properly validating boundaries. An authenticated client can trigger this issue by configuring excessive pointer barriers and generating cursor motion events, causing a buffer overflow. This vulnerability may lead to arbitrary code execution or cause the server to crash, resulting in a Denial of Service (DoS).
Published: n/a
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Arbitrary code execution
Action: Patch ASAP
AI Analysis

Impact

The X11 Xorg server contains a buffer overflow in the XFixes pointer barrier event handling. When an authenticated client configures more pointer barriers than the internal buffer can hold and then moves the cursor, the server writes beyond the buffer boundaries. If an attacker controls the overflow contents, they can execute arbitrary code or cause the server to terminate, leading to a denial of service.

Affected Systems

The vulnerability affects the X.Org X11 server. No specific version information is listed, so all installed instances of xorg-x11-server that accept pointer barrier configurations are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity level. The EPSS is not available, and the CISA KEV catalog, suggesting that publicly known exploits have not yet been observed. Because the flaw requires an authenticated client to manipulate pointer barriers, the attack surface is limited to trusted clients or local users with access to the server.

Generated by OpenCVE AI on October 8, 2026 at 13:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest X.Org X11 server release that contains the fixed buffer boundary checks.
  • Restrict or disable pointer barrier configuration for untrusted clients to prevent privilege escalation.
  • Apply access controls to limit which users can issue XFixes pointer barrier commands, ensuring only authorized processes can modify pointer barriers.

Generated by OpenCVE AI on October 8, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in xorg-x11-server. The server writes pointer barrier events into a fixed-size buffer without properly validating boundaries. An authenticated client can trigger this issue by configuring excessive pointer barriers and generating cursor motion events, causing a buffer overflow. This vulnerability may lead to arbitrary code execution or cause the server to crash, resulting in a Denial of Service (DoS).
Title xorg-x11-server: XFixes Pointer Barrier Event List Buffer Overflow
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-07T12:00:00Z

Links: CVE-2026-93519 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:00:05Z

Weaknesses