Impact
The vulnerability is an out-of-bounds read in libX11’s XIM attribute parser. It permits a malicious X server to supply malformed input that causes an X client to read memory beyond the intended buffer boundary, leading to a crash. The primary impact is a denial‑of‑service condition that disrupts the client application but does not provide code execution or data exposure, as described in the advisory.
Affected Systems
The affected product is the x.org libX11 library. Versions prior to 1.8.14 are vulnerable, as identified by the CNA. The vulnerability applies to any X client relying on the library’s XIM parsing functionality.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not available, and the issue is not listed in CISA’s KEV catalog, implying no confirmed widespread exploitation yet. The expected attack vector involves the attacker running a malicious X server or manipulating X connections to a patched client; the vulnerability is exploitable only if the client processes data from an attacker-controlled X server, so the threat is limited to environments where untrusted X servers are allowed.
OpenCVE Enrichment