Impact
An out‑of‑bounds read in libX11’s XIM trigger‑key registration parser can cause the parsing code to read beyond a buffer, leading to an abort of the client process. The resulting crash is a denial of service because attached X clients become unavailable.
Affected Systems
The flaw exists in the libX11 package from x.org prior to release 1.8.14. Any Linux or Unix‑like system using this version of libX11, including common desktop environments and X server clients, is potentially affected.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is a rogue or compromised X server that sends a crafted trigger‑key registration request; it does not require elevated privileges on the client and can be executed over the available X protocol connection. An attacker who can force the client to connect to a malicious server can trigger the OOB read and induce the crash.
OpenCVE Enrichment