Description
An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Published: 2026-09-28
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via crash
Action: Update libX11
AI Analysis

Impact

An out‑of‑bounds read in libX11’s XIM trigger‑key registration parser can cause the parsing code to read beyond a buffer, leading to an abort of the client process. The resulting crash is a denial of service because attached X clients become unavailable.

Affected Systems

The flaw exists in the libX11 package from x.org prior to release 1.8.14. Any Linux or Unix‑like system using this version of libX11, including common desktop environments and X server clients, is potentially affected.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is a rogue or compromised X server that sends a crafted trigger‑key registration request; it does not require elevated privileges on the client and can be executed over the available X protocol connection. An attacker who can force the client to connect to a malicious server can trigger the OOB read and induce the crash.

Generated by OpenCVE AI on September 28, 2026 at 10:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply libX11 1.8.14 or later from the vendor’s package repository.
  • For systems unable to upgrade immediately, enforce strict X server trust policies or limit network exposure of the X server port.
  • Monitor system logs for X client crashes and investigate recurring failures as potential exploitation attempts.

Generated by OpenCVE AI on September 28, 2026 at 10:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 28 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Title Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parser
First Time appeared X.org
X.org libx11
Weaknesses CWE-125
CPEs cpe:2.3:a:x.org:libx11:*:*:*:*:*:*:*:*
Vendors & Products X.org
X.org libx11
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-09-28T08:42:56.885Z

Reserved: 2026-09-21T09:33:25.369Z

Link: CVE-2026-94284

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T09:17:08.247

Modified: 2026-09-28T09:17:08.247

Link: CVE-2026-94284

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-28T08:42:56Z

Links: CVE-2026-94284 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T11:00:14Z

Weaknesses