Sceawere

Vulnerability Detail

CVE-2026-94282UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

libXi Out-of-Bounds Read Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.6
Creation Date
3h ago
Vendor
x.org
Product
libXi
Attack Type
CWE-125 Out-of-bounds read
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.6",
  "pubDate": "2026-09-28T09:17:08.003Z",
  "pubdate": "2026-09-28T09:17:08.003Z",
  "executiveSummary": "A vulnerability categorized as an out-of-bounds (OOB) read exists within libXi, the X Input Extension library, affecting versions prior to 1.8.4. This security flaw originates in the processing of XI2 (X Input Extension 2) enter, leave, and focus events.\nThe vulnerability allows a malicious or compromised X server to transmit crafted event data to an unsuspecting X client. By manipulating the cookie conversion process, an attacker can induce the client-side library to read memory beyond the intended bounds of allocated buffers.\nThe primary impact of this vulnerability is a denial-of-service (DoS) condition, resulting in the abrupt termination or crash of the attached X client application. This flaw poses a risk in environments where X clients interact with potentially untrusted X server instances. Exploitation requires the attacker to be in control of the X server protocol stream directed at the client; no specific user authentication is required at the application layer, as the vulnerability resides in the protocol handling logic of the library itself.",
  "technicalDetails": "The root cause of this vulnerability lies in insufficient boundary validation within libXi when handling XI2 cookie conversion for event types involving device focus, enter, and leave notifications. These events are processed by the library to translate wire-format data into internal XInput structures used by X clients.\nIn the context of the X11 protocol, XI2 events use a cookie mechanism to manage large event data. When the library processes these events, it expects the data to conform to specific size and format constraints defined by the XI2 extension protocol. A malicious X server can deviate from these specifications by sending malformed or unexpectedly small event structures, while reporting an length that suggests more data exists.\nThe attack flow commences when a client process makes a request to the X server, and the server responds with a crafted XI2 event. Upon reception, libXi initiates the cookie conversion logic. Because the validation routines fail to properly verify the relationship between the reported length of the event data and the actual memory allocated for the structure, the library attempts to access memory outside the bounds of the provided buffer. This OOB read operation occurs during the parsing of the XI2 event stream before the library returns the event to the application code.\nBecause libXi performs this read operation as part of its internal handling, the exploitation leads to memory access violations. Depending on the memory layout and the presence of memory protection mechanisms, this results in a segmentation fault or a process crash. Since this occurs within the context of the client process, the malicious server can effectively terminate any connected X client application by triggering this condition, representing a significant threat to application availability and system stability."
}
CVE-2026-94282: libXi Out-of-Bounds Read Vulnerability (MEDIUM Severity, CVSS: 5.6) | Sceawere