Impact
This vulnerability involves an out‑of‑bounds read in libXi’s XI2 enter/leave/focus cookie conversion function (wireToEnterLeave). When malformed or unexpected data is processed, the library can read beyond its intended buffer boundaries. The resulting memory read can trigger a crash or, in the worst case, leak sensitive data from adjacent memory. The effect is a sudden termination of the X client or server that uses libXi, leading to service disruption.
Affected Systems
The flaw exists in the libXi component of the X.Org X11 server and any application that relies on it for handling enter, leave, or focus events. Because no specific version information is available, any installation of libXi that has not applied an upstream fix could be vulnerable.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently widely exploited. The attack vector is likely local or remote within the X11 protocol; an attacker would need to generate or inject malformed XI2 event data. If successful, the exploit would result in a crash of an X client or server, causing a denial of service.
OpenCVE Enrichment