CVE-2026-94283
published 2026-09-28CVE-2026-94283: An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.20%
8.8th percentile
An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| x.org | libx11 | < 1.8.14 | 1.8.14 |
| x.org | libx11 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libX11: libX11: Denial of Service via out-of-bounds read in XIM attribute parser
vendor_redhat·2026-09-28·CVSS 6.5
CVE-2026-94283 [MEDIUM] CWE-125 libX11: libX11: Denial of Service via out-of-bounds read in XIM attribute parser
libX11: libX11: Denial of Service via out-of-bounds read in XIM attribute parser
A flaw was found in libX11. An out-of-bounds read vulnerability in the X Input Method (XIM) attribute parser allows a malicious X server to cause a Denial of Service (DoS) by crashing connected client applications when processing specially crafted attributes.
Package: libX11 (Red Hat Enterprise Linux 10) - Fix deferred
Package: libX11 (Red Hat Enterprise Linux 6) - Out of support scope
Package: libX11 (Red Hat Enterprise Linux 7) - Fix deferred
Package: libX11 (Red Hat Enterprise Linux 8) - Fix deferred
Package: libX11 (Red Hat Enterprise Linux 9) - Fix deferred
Package: libX11 (Red Hat Hardened Images) - Affected
GHSA
An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
ghsa_unreviewed·2026-09-28
CVE-2026-94283 [MEDIUM] CWE-125 An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-94283 libX11: libX11: Denial of Service via out-of-bounds read in XIM attribute parser [fedora-all]
bugzilla·2026-09-29·CVSS 6.5
CVE-2026-94283 [MEDIUM] CVE-2026-94283 libX11: libX11: Denial of Service via out-of-bounds read in XIM attribute parser [fedora-all]
CVE-2026-94283 libX11: libX11: Denial of Service via out-of-bounds read in XIM attribute parser [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Bugzilla
CVE-2026-94283 libX11: libX11: Denial of Service via out-of-bounds read in XIM attribute parser
bugzilla·2026-09-28·CVSS 6.5
CVE-2026-94283 [MEDIUM] CVE-2026-94283 libX11: libX11: Denial of Service via out-of-bounds read in XIM attribute parser
CVE-2026-94283 libX11: libX11: Denial of Service via out-of-bounds read in XIM attribute parser
An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
2026-09-28
Published