CVE-2026-34002
published 2026-05-05CVE-2026-34002: A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker…
PriorityP348critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.49%
39.2th percentile
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can lead to the exposure of sensitive information or cause the server to crash, resulting in a denial of service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| the_x.org_foundation | xorg-x11-server | — | — |
| tigervnc | tigervnc | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
X.org X11 Server X Keyboard Extension buffer access with incorrect length value
vuldb·2026-05-05·CVSS 6.1
CVE-2026-34002 [MEDIUM] X.org X11 Server X Keyboard Extension buffer access with incorrect length value
A vulnerability identified as problematic has been detected in X.org X11 Server. Affected is an unknown function of the component X Keyboard Extension. This manipulation causes buffer access with incorrect length value.
This vulnerability is registered as CVE-2026-34002. The attack needs to be launched locally. No exploit is available.
GHSA
GHSA-2q6x-pg74-2276: A flaw was found in the X
ghsa_unreviewed·2026-05-05
CVE-2026-34002 [MEDIUM] CWE-805 GHSA-2q6x-pg74-2276: A flaw was found in the X
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can lead to the exposure of sensitive information or cause the server to crash, resulting in a denial of service.
Red Hat
xorg: xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling
vendor_redhat·2026-05-05·CVSS 6.1
CVE-2026-34002 [MEDIUM] CWE-805 xorg: xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling
xorg: xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can lead to the exposure of sensitive information or cause the server to crash, resulting in a denial of service.
Statement: Moderate: This out-of-bounds read vulnerability in the X.Org X server's XKB modifier map handling could lead to information disclosure or service crashes. An attacker with access to the X11 server can trigger this without user intera
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34002 xorg-x11-server-Xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling [fedora-all]
bugzilla·2026-05-12·CVSS 9.1
CVE-2026-34002 [CRITICAL] CVE-2026-34002 xorg-x11-server-Xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling [fedora-all]
CVE-2026-34002 xorg-x11-server-Xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34002 xorg-x11-server: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling [fedora-all]
bugzilla·2026-05-12·CVSS 9.1
CVE-2026-34002 [CRITICAL] CVE-2026-34002 xorg-x11-server: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling [fedora-all]
CVE-2026-34002 xorg-x11-server: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34002 tigervnc: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling [fedora-all]
bugzilla·2026-05-12·CVSS 9.1
CVE-2026-34002 [CRITICAL] CVE-2026-34002 tigervnc: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling [fedora-all]
CVE-2026-34002 tigervnc: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34002 xorg: xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling
bugzilla·2026-03-25·CVSS 6.1
CVE-2026-34002 [MEDIUM] CVE-2026-34002 xorg: xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling
CVE-2026-34002 xorg: xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling
Out-of-bounds Read vulnerability in the XKB modifier map request handling of the X.Org X server. The function CheckModifierMap() processes wire data in a loop but does not sufficiently verify that the remaining bytes are within the bounds of the client request. As a result, the total number of keys processed can exceed the actual data supplied by the client, causing reads of uninitialized memory beyond the request buffer. An attacker with access to the X11 server can trigger this without user interaction, potentially disclosing memory and/or crashing the service.
https://access.redhat.com/errata/RHSA-2026:20547https://access.redhat.com/errata/RHSA-2026:20555https://access.redhat.com/errata/RHSA-2026:20557https://access.redhat.com/errata/RHSA-2026:20558https://access.redhat.com/errata/RHSA-2026:20560https://access.redhat.com/errata/RHSA-2026:20561https://access.redhat.com/errata/RHSA-2026:20562https://access.redhat.com/errata/RHSA-2026:20563https://access.redhat.com/errata/RHSA-2026:20575https://access.redhat.com/errata/RHSA-2026:20576https://access.redhat.com/errata/RHSA-2026:20590https://access.redhat.com/errata/RHSA-2026:21699https://access.redhat.com/errata/RHSA-2026:21712https://access.redhat.com/errata/RHSA-2026:21715https://access.redhat.com/errata/RHSA-2026:21716https://access.redhat.com/errata/RHSA-2026:21718https://access.redhat.com/errata/RHSA-2026:21741https://access.redhat.com/errata/RHSA-2026:21742https://access.redhat.com/errata/RHSA-2026:22424https://access.redhat.com/errata/RHSA-2026:22456https://access.redhat.com/errata/RHSA-2026:23254https://access.redhat.com/errata/RHSA-2026:23255https://access.redhat.com/errata/RHSA-2026:23496https://access.redhat.com/errata/RHSA-2026:24341https://access.redhat.com/security/cve/CVE-2026-34002https://bugzilla.redhat.com/show_bug.cgi?id=2451112
2026-05-05
Published