Description
A flaw was found in xorg-x11-server. In the X Keyboard Extension (XKB), key name memory is allocated with an insufficient buffer size compared to the maximum supported range. An authenticated local client can exploit this flaw by sending requests that modify the keycode range, triggering a heap-based buffer overflow. This vulnerability can lead to arbitrary code execution or cause a Denial of Service (DoS) by crashing the X server.
Published: n/a
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Heap buffer overflow leading to arbitrary code execution or denial of service
Action: Immediate Patch
AI Analysis

Impact

A flaw in the X Keyboard Extension of the Xorg X11 server allocates key name memory with an insufficient buffer size for the maximum supported range, allowing an authenticated local client to send requests that modify the keycode range and trigger a heap-based buffer overflow. This vulnerability can lead to arbitrary code execution or a denial of service by crashing the X server.

Affected Systems

The affected product is the Xorg X11 server. Specific vendor and version details are not enumerated in the provided data, but the issue applies to Linux/Unix environments running the Xorg server that support XKB functionality.

Risk and Exploitability

The CVSS score of 7.8 reflects a high risk for local attackers who can authenticate to the X server. With the EPSS score unavailable, the potential for exploitation remains uncertain, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a local authenticated client issuing XKB ChangeKeycodeRange requests, which can destabilize the X server or give the attacker code execution capabilities on the host system.

Generated by OpenCVE AI on October 8, 2026 at 13:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest patch for the Xorg X11 server that corrects the XKB keycode range memory allocation
  • Run the X server with the minimum required privileges and limit local client connections to trusted users
  • If a patch is not yet available, disable XKB ChangeKeycodeRange support or restrict XKB configuration changes through server configuration or security policies

Generated by OpenCVE AI on October 8, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in xorg-x11-server. In the X Keyboard Extension (XKB), key name memory is allocated with an insufficient buffer size compared to the maximum supported range. An authenticated local client can exploit this flaw by sending requests that modify the keycode range, triggering a heap-based buffer overflow. This vulnerability can lead to arbitrary code execution or cause a Denial of Service (DoS) by crashing the X server.
Title xorg-x11-server: XKB ChangeKeycodeRange Heap Out-of-Bounds Write
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-07T12:00:00Z

Links: CVE-2026-93520 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:00:05Z

Weaknesses