Impact
An out-of-bounds read occurs in libX11's byte‑oriented codeset parser when the library is older than 1.8.14. The flaw is a buffer overread, classified as CWE‑125, and can be triggered by a malicious X server to crash attached X clients. The primary consequence is a client‑side denial of service, disrupting graphical applications without leaking data or escalating privileges.
Affected Systems
The vulnerability affects the x.org libX11 library from any vendor providing the open‑source X.Org implementation. All installations of libX11 before version 1.8.14 are susceptible; newer releases (1.8.14 and later) contain the fix.
Risk and Exploitability
The CVSS base score of 5.1 indicates moderate severity. The EPSS score is not available, but the weakness can be abused by devices that can act as an X server to attached clients, meaning it requires the attacker to run a malicious server on the network where the client will connect. Because it is a client‑side crash and not a remote code execution, the risk is primarily operational. It is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet, but the potential for disruption in multi‑user X environments remains.
OpenCVE Enrichment