Sceawere

Vulnerability Detail

CVE-2026-94287UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

libXpm Unsigned Underflow Denial Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
3h ago
Vendor
x.org
Product
libXpm
Attack Type
CWE-1050 Excessive platform resource consumption within a loop
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-28T09:17:08.577Z",
  "pubdate": "2026-09-28T09:17:08.577Z",
  "executiveSummary": "A critical vulnerability exists in the write path of libXpm versions prior to 3.5.19, stemming from an unsigned integer underflow condition.\nThis vulnerability allows a local attacker to trigger a denial-of-service (DoS) state characterized by unbounded CPU consumption and systemic memory exhaustion.\nThe flaw resides within the library's image processing routines, where improper handling of unsigned arithmetic operations leads to predictable memory management failures.\nSuccessful exploitation requires the attacker to influence the input processed by the vulnerable write functions, typically through the supply of a maliciously crafted Xpm image file.\nThe primary impact is the complete degradation of service availability on the affected system, as the uncontrolled resource allocation leads to process or system-wide instability.\nWhile the vulnerability is local in nature, it poses significant risk to systems that process untrusted image data, such as desktop environments or graphics processing services utilizing libXpm.",
  "technicalDetails": "The vulnerability is located within the write path functions of libXpm, specifically where size calculations for buffers are performed prior to memory allocation or data processing operations.\nThe root cause is an unsigned integer underflow occurring when the library calculates dimensions or offsets for Xpm image data. When an attacker provides crafted input, an arithmetic operation involving unsigned integers results in a value smaller than the intended range, effectively wrapping around to a very large positive value due to modular arithmetic.\nIn the context of the libXpm write path, this underflow results in an incorrect size being passed to internal memory management or loop control functions. Specifically, a calculation that should result in a small positive integer instead produces a near-maximum value for the unsigned data type (e.g., 2^n - 1).\nWhen this massive, incorrect value is subsequently utilized as a loop counter or a memory allocation parameter, the application attempts to perform an operation that is effectively unbounded. This causes the library to enter an infinite or extremely long-running loop, leading to 100% CPU utilization.\nSimultaneously, if the underflowed value is used to request a memory buffer, the application may attempt to allocate an excessively large block of memory, causing the operating system to trigger the Out-Of-Memory (OOM) killer or experience extreme memory pressure and swapping, resulting in system-wide service disruption.\nThe exploitation flow involves the attacker passing a specially crafted Xpm image to an application linked against a vulnerable version of libXpm. Upon attempting to write or convert the file, the library's internal logic encounters the underflow condition, triggering the aforementioned resource exhaustion.\nBecause the logic flaw is deeply embedded in the image serialization process, the application does not need to perform complex memory corruption to achieve the DoS; the exhaustion of CPU and memory is a deterministic consequence of the flawed arithmetic.\nThe vulnerability affects libXpm versions before 3.5.19. Since libXpm is a core component for X Window System graphical applications, the attack surface includes any application that uses the library to parse or write Xpm image formats, regardless of the application's specific role as a user-space utility or a daemon."
}
CVE-2026-94287: libXpm Unsigned Underflow Denial Service (MEDIUM Severity, CVSS: 5.5) | Sceawere