Impact
The vulnerability is an out‑of‑bounds read in the XI2 class parser of libXi, caused by insufficient bounds checking in size_classes() and copy_classes(). It can lead to a crash of the X client, which is a denial of service attack. The weakness is classified as CWE‑125, which refers to improper bounds checking that can expose sensitive data or cause program termination.
Affected Systems
The affected product is the X.Org libXi library. All releases prior to version 1.8.4 are vulnerable; the library is named x.org:libXi in the Common Platform Enumeration taxonomy.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No exploitation vector is reported in the CISA KEV catalog, and the EPSS score is not available, suggesting either a low or undetermined exploitation likelihood. The vulnerability is exploitable by malicious servers that initiate communication with a vulnerable X client, as the attacker can supply crafted class data to trigger the out‑of‑bounds read and cause a crash.
OpenCVE Enrichment