Sceawere
Vulnerability Detail
CVE-2026-94286UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
libXtst Out-of-Bounds Read Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- x.org
- Product
- libXtst
- Attack Type
- CWE-126 Buffer over-read
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-28T09:17:08.463Z",
"pubdate": "2026-09-28T09:17:08.463Z",
"executiveSummary": "A critical out-of-bounds read vulnerability has been identified in the RECORD extension reply parser of libXtst prior to version 1.2.6. This flaw allows a malicious X server to provide specially crafted responses to an X client using the libXtst library.\nThe vulnerability type is an out-of-bounds read, which manifests when the library fails to properly validate the bounds of data returned by the server. An attacker operating a malicious X server can exploit this by sending a malformed RECORD reply, triggering an out-of-bounds memory access within the client process.\nThe primary impact of this vulnerability is a denial-of-service (DoS) condition, resulting in the termination or crash of the attached X client. This poses a significant risk to the stability and availability of client applications relying on libXtst. Exploitation requires the attacker to position themselves as an X server to which the victim client connects. No specialized authentication is typically required if the client is configured to connect to an untrusted server. Users are advised to update libXtst to version 1.2.6 or later to remediate the underlying flaw.",
"technicalDetails": "The vulnerability resides in the RECORD extension reply parsing logic within the libXtst library. The RECORD extension allows X clients to record and replay X protocol traffic. When a client requests a RECORD extension operation, it expects a corresponding reply from the X server containing specific data structures.\nThe root cause of this vulnerability is insufficient boundary checking during the deserialization of the RECORD reply packets. When the libXtst library processes the response from an X server, it reads the data stream to reconstruct the reply structure. If the X server provides a maliciously crafted reply that misrepresents the size or length of the data fields—specifically in the context of reply parsing—the library may attempt to read memory addresses beyond the buffer allocated for that specific transaction.\nThe attack flow initiates when an X client, utilizing libXtst, establishes a connection to a malicious X server. The attacker, controlling the X server environment, waits for the client to invoke RECORD extension functionality. Once triggered, the attacker sends a crafted RECORD reply packet containing header or length fields that deviate from protocol specifications. Specifically, if the library uses these values to calculate offsets for subsequent data reads without proper bounds validation, it results in an out-of-bounds memory access.\nBecause the libXtst library operates within the memory space of the client process, the out-of-bounds read typically results in a segmentation fault or a similar memory access violation error. This causes the client application to crash immediately. The vulnerability is exploitable by any malicious entity that can masquerade as a legitimate X server; therefore, if a user connects to an untrusted or compromised X server, the client is at risk of being crashed.\nThe scope of the impact is localized to the client-side process. While the current description focuses on a crash, out-of-bounds reads can theoretically be leveraged in sophisticated chains to leak sensitive memory information, although the primary documented outcome here is service disruption. The flaw is present in all versions of libXtst prior to 1.2.6. Because this occurs at the library level, it affects any application linked against the vulnerable versions of libXtst, regardless of the application's internal logic, provided it uses the RECORD extension features."
}