Sceawere
Vulnerability Detail
CVE-2026-94285UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
libX11 Out-of-Bounds Read Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.1
- Creation Date
- 3h ago
- Vendor
- x.org
- Product
- libX11
- Attack Type
- CWE-125 Out-of-bounds read
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.1",
"pubDate": "2026-09-28T09:17:08.353Z",
"pubdate": "2026-09-28T09:17:08.353Z",
"executiveSummary": "A vulnerability has been identified in the libX11 library's byte-oriented codeset parser, categorized as an out-of-bounds read.\nThe flaw affects versions of libX11 prior to 1.8.14.\nThe vulnerability allows a malicious X server to trigger a denial-of-service condition against connected X clients.\nThis occurs when the client processes specifically crafted or malformed data provided by an X server during the codeset parsing sequence.\nThe impact is primarily focused on application instability, leading to client crashes.\nBecause X clients typically trust the X server to which they connect, an attacker controlling the server can exploit this by forcing the client to read beyond its allocated memory boundaries, leading to memory access violations.\nThis issue represents a significant risk for environments where X clients may connect to potentially untrusted or compromised X servers.\nNo specific authentication is required to initiate the attack, as the exploitation is facilitated via the inherent client-server protocol interaction.",
"technicalDetails": "The vulnerability resides within the byte-oriented codeset parser of libX11, a foundational library for the X Window System that handles client-side interaction with the X server.\nThe root cause is an out-of-bounds read condition triggered when the parser fails to properly validate the bounds of data input while processing codeset-related structures.\nIn the X11 protocol, the client-server interaction involves the exchange of various data structures, including those defining character sets and encoding mappings. The parser responsible for interpreting these byte-oriented sequences does not enforce strict boundary checks on the input length or the internal offsets used to navigate the data buffer.\nWhen a malicious X server supplies a carefully crafted response containing malformed or unexpected data lengths during the codeset initialization or handling process, the parser may increment internal pointers beyond the valid memory region allocated for the input buffer.\nThis out-of-bounds read occurs because the parser logic does not correctly verify that the incoming byte sequence aligns with the expected format or length definitions before performing memory access operations.\nThe exploitation flow proceeds as follows: First, an attacker initiates a connection from a malicious or controlled X server to a targeted X client. Second, the client initiates the standard codeset negotiation or parsing sequence as dictated by the protocol. Third, the malicious server transmits a specially crafted payload designed to trigger the out-of-bounds condition. Fourth, the libX11 parser attempts to read from a memory address outside the authorized bounds of the input buffer.\nThe immediate effect of this memory access violation is an unhandled signal, such as a segmentation fault (SIGSEGV), which causes the affected X client process to terminate unexpectedly.\nWhile the primary impact documented is a denial-of-service, out-of-bounds read vulnerabilities can theoretically lead to information disclosure if the memory adjacent to the read contains sensitive data, although the primary crash scenario remains the most prevalent outcome in this context.\nThis vulnerability is present in all versions of libX11 prior to 1.8.14. It is applicable in any environment where an X client connects to a server, and requires no elevated privileges from the attacker beyond the capability to present as an X server to the client."
}