Impact
An unsigned underflow in the write path of libXpm allows a local attacker to cause the library to enter an unbounded loop and exhaust system memory, resulting in a denial of service. The flaw is identified as CWE-1050, an integer underflow issue that leads to uncontrolled resource consumption.
Affected Systems
The vulnerability affects the libXpm component of the X.Org project. Any installation using libXpm prior to version 3.5.19 is impacted. Users of older releases should verify their installed library version against the CPE 2.3 identifier for x.org:libxpm and consider updates.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, but the local nature of the required attacker access limits the attack surface. This vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation reports yet. However, any local user with sufficient privileges can trigger excessive CPU usage, triggering potential resource starvation for the entire system. The attacker must execute code that triggers libXpm’s write API, and the vulnerability does not require elevated privileges beyond local access.
OpenCVE Enrichment