PatchSiren

x.org CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM x.org CVE published 2026-09-28

CVE-2026-94287

A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion. This issue affects systems using libXpm, particularly those with unpatched versions prior to 3.5.19. The vulnerability allows local attackers to exploit the unsigned underflow, potentially leading to denial of service attacks. Defend [truncated]

HIGH x.org CVE published 2026-09-28

CVE-2026-94286

An out-of-bounds read in libXtst's RECORD reply parser could be used by malicious X servers to crash attached X clients. This issue affects libXtst before version 1.2.6 and has been assigned a CVSS score of 7.1. The CVE record was published on 2026-09-28T09:17:08.463Z and has not been modified since then. Defenders should assess exposure and prioritize remediation based on X client and server configuratio [truncated]

MEDIUM x.org CVE published 2026-09-28

CVE-2026-94285

An out-of-bounds read in libX11's byte-oriented codeset parser could be used by malicious X servers to crash attached X clients. This CVE was published on 2026-09-28T09:17:08.353Z and has not been modified since then. The NVD entry is currently 5.1 MEDIUM. Defenders should assess exposure, prioritize remediation, and verify X client and server configurations.

MEDIUM x.org CVE published 2026-09-28

CVE-2026-94284

An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser could allow malicious X servers to crash attached X clients. This issue exists in libX11 before version 1.8.14 and has been assigned a CVSS score of 5.5, indicating a medium severity level. The vulnerability affects systems using libX11 versions before 1.8.14, and defenders should prioritize verifying and updating to this [truncated]

MEDIUM x.org CVE published 2026-09-28

CVE-2026-94283

An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser could allow malicious X servers to crash attached X clients. This issue exists in libX11 before version 1.8.14 and has been assigned a CVSS score of 6.5, indicating a medium severity level. The vulnerability's impact is primarily related to potential service disruption and the need for verification and patching. System a [truncated]

MEDIUM x.org CVE published 2026-09-28

CVE-2026-94282

An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client. This vulnerability affects X server and client systems using libXi versions prior to 1.8.4. Defenders should assess exposure and prioritize updates to prevent potential crashes. The vulnerability has a CVSS score of 5.6 and a severity of MEDIUM. [truncated]

HIGH X.Org CVE published 2026-07-08

CVE-2026-56003

CVE-2026-56003 is a heap buffer overflow vulnerability in libXfont2, caused by missing size checking in the property buffer when parsing PCF files in the ComputeScaledProperties() function. This could be exploited by attackers using authenticated X clients to execute code within the X server. The vulnerability has a high impact on systems that use libXfont2, including Linux distributions and X11 environments.

HIGH X.Org CVE published 2026-07-08

CVE-2026-56002

CVE-2026-56002 is a heap buffer overflow vulnerability in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8, allowing authenticated X clients to execute code within the X server. This vulnerability affects systems using libXfont2, particularly those with untrusted clients connecting to X servers. Users should apply patches or updates to mitigate this vulnerability. The issue was [truncated]

HIGH X.Org CVE published 2026-07-08

CVE-2026-56001

CVE-2026-56001 is a heap buffer overflow vulnerability in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32-bit size. This could be used by attackers able to access the X Server to execute code within the X server context. The vulnerability exists in the BitmapScaleBitmaps function of libXfont2, a library used for font rendering in the X Window System. An overflowing 32-bit size can le [truncated]

CRITICAL X.Org CVE published 2026-07-08

CVE-2026-56000

CVE-2026-56000 is a critical vulnerability in xorg-server before 21.2.24 and xwayland before 24.1.13. Local attackers with an X connection can exploit this vulnerability to cause a Heap Use After Free. The vulnerability is due to CommonMakeCurrent() pointing into potentially reallocated memory. The affected products are xorg-server and xwayland, and the vulnerability class is Heap Use After Free. The like [truncated]

HIGH X.Org CVE published 2026-07-08

CVE-2026-55999

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks. This vulnerability has a high CVSS score of 8.5, indicating a high severity. The vulnerability exists in the X server, specifically in the SetFont function. Users of xorg-server before versi [truncated]

CRITICAL X.org CVE published 2017-02-01

CVE-2016-10164

CVE-2016-10164 is a critical libXpm flaw affecting versions before 3.5.12. When a program parses XPM extensions on a 64-bit platform, crafted input can trigger integer overflows in the number of extensions or their combined length, leading to a heap-based buffer overflow. The stated impact includes denial of service and potential arbitrary code execution.