CVE-2026-94285
published 2026-09-28CVE-2026-94285: An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
PriorityP419medium5.1CVSS 3.1
AVLACLPRNUINSUCLINAL
EPSS
0.11%
1.3th percentile
An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| x.org | libx11 | < 1.8.14 | 1.8.14 |
| x.org | libx11 | — | — |
CVSS provenance
nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libX11: libX11: Denial of Service via out-of-bounds read in byte-oriented codeset parser
vendor_redhat·2026-09-28·CVSS 5.1
CVE-2026-94285 [MEDIUM] CWE-125 libX11: libX11: Denial of Service via out-of-bounds read in byte-oriented codeset parser
libX11: libX11: Denial of Service via out-of-bounds read in byte-oriented codeset parser
A flaw was found in libX11. An out-of-bounds read vulnerability in the byte-oriented codeset parser allows a malicious X Window System server to cause a Denial of Service (DoS) by crashing connected client applications. This issue may also allow the server to access limited memory contents from the client.
Package: libX11 (Red Hat Enterprise Linux 10) - Fix deferred
Package: libX11 (Red Hat Enterprise Linux 6) - Out of support scope
Package: libX11 (Red Hat Enterprise Linux 7) - Fix deferred
Package: libX11 (Red Hat Enterprise Linux 8) - Fix deferred
Package: libX11 (Red Hat Enterprise Linux 9) - Fix deferred
Package: libX11 (Red Hat Hardened Images) - Affected
VulDB
x.org libX11 up to 1.8.13 Byte-Oriented Codeset Parser out-of-bounds (Nessus ID 350909 / WID-SEC-2026-3606)
vuldb·2026-09-29·CVSS 5.1
CVE-2026-94285 [MEDIUM] x.org libX11 up to 1.8.13 Byte-Oriented Codeset Parser out-of-bounds (Nessus ID 350909 / WID-SEC-2026-3606)
A vulnerability was found in x.org libX11 up to 1.8.13. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Byte-Oriented Codeset Parser. Executing a manipulation can lead to out-of-bounds read.
The identification of this vulnerability is CVE-2026-94285. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
ghsa_unreviewed·2026-09-28
CVE-2026-94285 [MEDIUM] CWE-125 An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-94285 libX11: libX11: Denial of Service via out-of-bounds read in byte-oriented codeset parser [fedora-all]
bugzilla·2026-09-29·CVSS 5.1
CVE-2026-94285 [MEDIUM] CVE-2026-94285 libX11: libX11: Denial of Service via out-of-bounds read in byte-oriented codeset parser [fedora-all]
CVE-2026-94285 libX11: libX11: Denial of Service via out-of-bounds read in byte-oriented codeset parser [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Bugzilla
CVE-2026-94285 libX11: libX11: Denial of Service via out-of-bounds read in byte-oriented codeset parser
bugzilla·2026-09-28·CVSS 5.1
CVE-2026-94285 [MEDIUM] CVE-2026-94285 libX11: libX11: Denial of Service via out-of-bounds read in byte-oriented codeset parser
CVE-2026-94285 libX11: libX11: Denial of Service via out-of-bounds read in byte-oriented codeset parser
An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
2026-09-28
Published