CVE-2026-94284
published 2026-09-28CVE-2026-94284: An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash…
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.10%
0.9th percentile
An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| x.org | libx11 | < 1.8.14 | 1.8.14 |
| x.org | libx11 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
x.org libX11 up to 1.8.13 XIM trigger-key registration parser out-of-bounds (Nessus ID 350906 / WID-SEC-2026-3606)
vuldb·2026-09-29·CVSS 5.5
CVE-2026-94284 [MEDIUM] x.org libX11 up to 1.8.13 XIM trigger-key registration parser out-of-bounds (Nessus ID 350906 / WID-SEC-2026-3606)
A vulnerability was found in x.org libX11 up to 1.8.13. It has been rated as problematic. Affected by this issue is some unknown functionality of the component XIM trigger-key registration parser. The manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2026-94284. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
GHSA
An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
ghsa_unreviewed·2026-09-28
CVE-2026-94284 [MEDIUM] CWE-125 An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Red Hat
libX11: libX11: Denial of Service via out-of-bounds read in XIM trigger-key registration parser
vendor_redhat·2026-09-28·CVSS 5.5
CVE-2026-94284 [MEDIUM] CWE-125 libX11: libX11: Denial of Service via out-of-bounds read in XIM trigger-key registration parser
libX11: libX11: Denial of Service via out-of-bounds read in XIM trigger-key registration parser
A flaw was found in libX11. An out-of-bounds read vulnerability exists in the X Input Method (XIM) trigger-key registration parser. A malicious X server can exploit this flaw by sending specially crafted trigger-key registration data to connected client applications, causing them to crash and resulting in a Denial of Service (DoS).
Package: libX11 (Red Hat Enterprise Linux 10) - Fix deferred
Package: libX11 (Red Hat Enterprise Linux 6) - Out of support scope
Package: libX11 (Red Hat Enterprise Linux 7) - Fix deferred
Package: libX11 (Red Hat Enterprise Linux 8) - Fix deferred
Package: libX11 (Red Hat Enterprise Linux 9) - Fix deferred
Package: libX11 (Red Hat Hardened Images) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-94284 libX11: libX11: Denial of Service via out-of-bounds read in XIM trigger-key registration parser [fedora-all]
bugzilla·2026-09-29·CVSS 5.5
CVE-2026-94284 [MEDIUM] CVE-2026-94284 libX11: libX11: Denial of Service via out-of-bounds read in XIM trigger-key registration parser [fedora-all]
CVE-2026-94284 libX11: libX11: Denial of Service via out-of-bounds read in XIM trigger-key registration parser [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Bugzilla
CVE-2026-94284 libX11: libX11: Denial of Service via out-of-bounds read in XIM trigger-key registration parser
bugzilla·2026-09-28·CVSS 5.5
CVE-2026-94284 [MEDIUM] CVE-2026-94284 libX11: libX11: Denial of Service via out-of-bounds read in XIM trigger-key registration parser
CVE-2026-94284 libX11: libX11: Denial of Service via out-of-bounds read in XIM trigger-key registration parser
An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
2026-09-28
Published