Sceawere
Vulnerability Detail
CVE-2026-94284UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
libX11 Out-of-Bounds Read Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 3h ago
- Vendor
- x.org
- Product
- libX11
- Attack Type
- CWE-125 Out-of-bounds read
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-28T09:17:08.247Z",
"pubdate": "2026-09-28T09:17:08.247Z",
"executiveSummary": "This vulnerability is an out-of-bounds (OOB) read flaw discovered within the XIM (X Input Method) trigger-key registration parser of the libX11 library.\nThe vulnerability allows a malicious or compromised X server to send specially crafted data to an attached X client, triggering an out-of-bounds memory read during the parsing process.\nThe primary impact of this vulnerability is a denial-of-service (DoS) condition, resulting in the abrupt termination or crash of the target X client application.\nAffected products include libX11 versions prior to 1.8.14.\nThe risk is categorized as elevated for environments where X clients interact with untrusted or potentially compromised X servers.\nSuccessful exploitation requires the attacker to have control over an X server to which the vulnerable X client connects, or the ability to intercept and modify the communication stream between the X client and a legitimate server.\nNo authentication is required by the victim application to trigger the flaw, as the vulnerability is inherent to the X11 protocol handling within the library itself.",
"technicalDetails": "The vulnerability resides in the XIM (X Input Method) protocol processing logic within libX11, specifically within the functions responsible for parsing trigger-key registration sequences.\nThe root cause is improper bounds checking when processing input data received from an X server during the XIM registration phase. When the libX11 library parses a trigger-key registration request, it relies on length fields provided by the server to determine how much data to read from the input buffer.\nIf a malicious X server provides an inconsistent or maliciously crafted length value that does not correspond to the actual available data within the buffer, the parser may attempt to read memory beyond the allocated buffer boundaries.\nThis out-of-bounds read operation typically leads to a segmentation fault or a memory access violation, forcing the client process to crash.\nThe attack flow begins when an X client initiates a connection or interacts with an X server. During the XIM protocol negotiation, the X server sends a crafted registration packet. The libX11 client, upon receiving this packet, invokes the vulnerable parsing logic.\nBecause the parser lacks rigorous verification of the input length against the physical bounds of the allocated stack or heap memory, the pointer increment exceeds the expected data size. This triggers the OOB read when the code attempts to access the next expected byte or structure field.\nIn terms of privilege and exposure, the vulnerability is exposed whenever an X client is configured to use XIM and connects to a server. The exploitation does not require the attacker to have prior authentication to the client process, as the vulnerability is reached through the standard X11 protocol communication channel.\nWhile the primary documented impact is a crash, the potential for information disclosure exists depending on whether the OOB read allows reading sensitive adjacent memory contents back to the attacker or causes unstable state execution.\nThe vulnerability affects all libX11 versions prior to 1.8.14, as these versions lack the necessary input validation checks for the XIM trigger-key registration packets."
}