Description
A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.
Published: 2026-09-28
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

An unsigned underflow in the write path of libXpm allows a local attacker to cause the library to enter an unbounded loop and exhaust system memory, resulting in a denial of service. The flaw is identified as CWE-1050, an integer underflow issue that leads to uncontrolled resource consumption.

Affected Systems

The vulnerability affects the libXpm component of the X.Org project. Any installation using libXpm prior to version 3.5.19 is impacted. Users of older releases should verify their installed library version against the CPE 2.3 identifier for x.org:libxpm and consider updates.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, but the local nature of the required attacker access limits the attack surface. This vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation reports yet. However, any local user with sufficient privileges can trigger excessive CPU usage, triggering potential resource starvation for the entire system. The attacker must execute code that triggers libXpm’s write API, and the vulnerability does not require elevated privileges beyond local access.

Generated by OpenCVE AI on September 28, 2026 at 10:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade libXpm to version 3.5.19 or later to remove the integer underflow in the write path.
  • Restrict local users who can execute code that utilizes libXpm, limiting privilege escalation paths.
  • Configure system resource limits for processes that load libXpm to prevent catastrophic CPU or memory usage.

Generated by OpenCVE AI on September 28, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-191
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 28 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Description A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.
Title Denial of service via unsigned underflow in libXpm's write path
First Time appeared X.org
X.org libxpm
Weaknesses CWE-1050
CPEs cpe:2.3:a:x.org:libxpm:*:*:*:*:*:*:*:*
Vendors & Products X.org
X.org libxpm
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-09-28T08:57:24.943Z

Reserved: 2026-09-21T09:33:25.369Z

Link: CVE-2026-94287

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T09:17:08.577

Modified: 2026-09-28T09:17:08.577

Link: CVE-2026-94287

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-28T08:57:24Z

Links: CVE-2026-94287 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T10:30:15Z

Weaknesses
  • CWE-1050

    Excessive Platform Resource Consumption within a Loop

  • CWE-191

    Integer Underflow (Wrap or Wraparound)