PatchSiren cyber security CVE debrief
CVE-2026-33999 Red Hat CVE debrief
A HIGH severity integer underflow vulnerability in the X.Org X server's XKB compatibility map handling allows attackers with local or remote X11 server access to trigger buffer read overruns, potentially causing denial of service or memory-safety violations. The vulnerability was published on 2026-04-23 and last modified on 2026-05-20. Multiple Red Hat Security Advisories have been issued addressing this flaw across various product versions.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-23
- Original CVE updated
- 2026-07-15
- Advisory published
- 2026-04-23
- Advisory updated
- 2026-07-15
Who should care
Organizations running X.Org X server deployments, particularly those enabling remote X11 access or multi-user environments with XKB functionality. System administrators managing Red Hat Enterprise Linux and derivative distributions should prioritize patch deployment given the multiple RHSA advisories issued.
Technical summary
CVE-2026-33999 is an integer underflow vulnerability (CWE-191) in the X.Org X server's XKB (X Keyboard Extension) compatibility map handling code. The flaw occurs when processing XKB compatibility map data, where an integer underflow can lead to a buffer read overrun. An attacker with local or remote access to an X11 server can exploit this to trigger memory-safety violations. The vulnerability has a CVSS 3.1 score of 7.8 (HIGH) with attack vector LOCAL, low attack complexity, low privileges required, and no user interaction needed, resulting in high impacts to confidentiality, integrity, and availability. Red Hat has issued multiple security advisories (RHSA-2026:10739, RHSA-2026:11352, RHSA-2026:11369, RHSA-2026:11388, RHSA-2026:11656, RHSA-2026:11692, RHSA-2026:13414, and others) indicating active remediation across their product portfolio. The CVE was published on 2026-04-23 and last modified on 2026-05-20.
Defensive priority
HIGH
Recommended defensive actions
- Apply relevant Red Hat Security Advisory patches as they become available for your product versions
- Restrict X11 server access to trusted hosts and users where patching is not immediately feasible
- Monitor X server logs for anomalous XKB-related activity
- Review network segmentation to limit remote X11 exposure
- Validate X.Org X server version against vendor security bulletins
Evidence notes
CVE description confirms integer underflow in XKB compatibility map handling with CVSS 7.8 (HIGH). CWE-191 (Integer Underflow) identified by Red Hat. Multiple RHSA errata published indicating active remediation across Red Hat product portfolio.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-33999 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-33999
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-33999 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33999
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:10739
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:11352
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:11369
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:11388
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:11656
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:11692
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:13414
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.