CVE-2026-34000
published 2026-05-05CVE-2026-34000: A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and…
PriorityP352critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.49%
38.8th percentile
A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| the_x.org_foundation | xorg-x11-server | — | — |
| tigervnc | tigervnc | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.
vendor_redhat·2026-05-05·CVSS 6.1
CVE-2026-34000 [MEDIUM] CWE-125 xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.
xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.
A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server.
Statement: This out-of-bounds read vulnerability in the X.Org X server's XKB geometry processing could allow an attacker to leak memory contents or cause a denial of service. Exploitation req
VulDB
X.org X11 Server CheckSetGeom/XkbAddGeomKeyAlias out-of-bounds
vuldb·2026-05-05·CVSS 6.1
CVE-2026-34000 [MEDIUM] X.org X11 Server CheckSetGeom/XkbAddGeomKeyAlias out-of-bounds
A vulnerability labeled as critical has been found in X.org X11 Server. Affected by this vulnerability is the function CheckSetGeom/XkbAddGeomKeyAlias. Such manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-34000. The attack needs to be performed locally. There is not any exploit available.
GHSA
GHSA-x7p4-8jjf-qcp4: A flaw was found in the X
ghsa_unreviewed·2026-05-05
CVE-2026-34000 [MEDIUM] CWE-125 GHSA-x7p4-8jjf-qcp4: A flaw was found in the X
A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34000 xorg-x11-server-Xwayland: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing. [fedora-all]
bugzilla·2026-05-13·CVSS 9.1
CVE-2026-34000 [CRITICAL] CVE-2026-34000 xorg-x11-server-Xwayland: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing. [fedora-all]
CVE-2026-34000 xorg-x11-server-Xwayland: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34000 xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.
bugzilla·2026-03-25·CVSS 6.1
CVE-2026-34000 [MEDIUM] CVE-2026-34000 xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.
CVE-2026-34000 xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.
Out-of-bounds Read vulnerability in the XKB geometry processing of the X.Org X server. The issue is located in CheckSetGeom(), where bounds checking is performed using only the first key name of each alias entry (alias vs. real key name). Because the second name is not properly validated, XkbAddGeomKeyAlias may read uninitialized or out-of-bounds memory when processing a crafted request. An attacker who can connect to the X11 server (locally or via forwarded remote sessions) can trigger this without user interaction, potentially leaking memory contents and/or causing a crash.
https://access.redhat.com/errata/RHSA-2026:19342https://access.redhat.com/errata/RHSA-2026:20547https://access.redhat.com/errata/RHSA-2026:20555https://access.redhat.com/errata/RHSA-2026:20557https://access.redhat.com/errata/RHSA-2026:20558https://access.redhat.com/errata/RHSA-2026:20560https://access.redhat.com/errata/RHSA-2026:20561https://access.redhat.com/errata/RHSA-2026:20562https://access.redhat.com/errata/RHSA-2026:20563https://access.redhat.com/errata/RHSA-2026:20575https://access.redhat.com/errata/RHSA-2026:20576https://access.redhat.com/errata/RHSA-2026:20590https://access.redhat.com/errata/RHSA-2026:21699https://access.redhat.com/errata/RHSA-2026:21712https://access.redhat.com/errata/RHSA-2026:21715https://access.redhat.com/errata/RHSA-2026:21716https://access.redhat.com/errata/RHSA-2026:21718https://access.redhat.com/errata/RHSA-2026:21741https://access.redhat.com/errata/RHSA-2026:21742https://access.redhat.com/errata/RHSA-2026:22424https://access.redhat.com/errata/RHSA-2026:22456https://access.redhat.com/errata/RHSA-2026:23254https://access.redhat.com/errata/RHSA-2026:23255https://access.redhat.com/errata/RHSA-2026:23496https://access.redhat.com/errata/RHSA-2026:24341https://access.redhat.com/security/cve/CVE-2026-34000https://bugzilla.redhat.com/show_bug.cgi?id=2451107
2026-05-05
Published