PatchSiren cyber security CVE debrief
CVE-2026-34003 Red Hat CVE debrief
A local out-of-bounds memory access vulnerability exists in the X.Org X server's XKB key types request validation. An attacker with local access can send a crafted request to trigger the flaw, potentially causing information disclosure, server crash (DoS), or higher impact outcomes in certain configurations. The vulnerability was published on 2026-04-23 and last modified on 2026-05-20. Multiple Red Hat security advisories have been issued addressing this issue. The weakness is classified as CWE-125 (Out-of-bounds Read).
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-23
- Original CVE updated
- 2026-07-15
- Advisory published
- 2026-04-23
- Advisory updated
- 2026-07-15
Who should care
Organizations running X.Org X server on Linux systems, particularly those with multi-user environments where untrusted users have local access. System administrators managing Red Hat Enterprise Linux deployments should prioritize patching based on the available RHSA advisories.
Technical summary
The vulnerability exists in the XKB (X Keyboard Extension) key types request validation within the X.Org X server. Insufficient bounds checking on key types requests allows a local attacker to trigger out-of-bounds memory access. The attack vector is local (AV:L) with low attack complexity (AC:L) and low privileges required (PR:L). Successful exploitation can result in high impact to confidentiality, integrity, and availability (C:H/I:H/A:H). The flaw is classified as CWE-125 (Out-of-bounds Read).
Defensive priority
high
Recommended defensive actions
- Apply vendor patches from Red Hat security advisories for affected systems
- Restrict local access to X server where patching is not immediately feasible
- Monitor for anomalous X server crashes or unexpected memory access patterns
- Review X server configuration for exposure to untrusted local users
- Validate XKB extension usage and consider disabling if not required
Evidence notes
Vulnerability description sourced from official CVE record and NVD entry. Red Hat has issued multiple RHSA advisories (RHSA-2026:10739, RHSA-2026:11352, RHSA-2026:11369, RHSA-2026:11388, RHSA-2026:11656, RHSA-2026:11692, RHSA-2026:13414, RHSA-2026:19125, RHSA-2026:19342, RHSA-2026:19343, RHSA-2026:19344) indicating patches are available for affected Red Hat Enterprise Linux systems. Bugzilla reference 2451113 tracks this issue. CVSS 3.1 vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-34003 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-34003
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-34003 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34003
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:10739
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:11352
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:11369
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:11388
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:11656
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:11692
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:13414
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.