CVE-2016-7943: Critical severity Fedoraproject Fedora vulnerability
Published Dec 13, 2016
·Updated
Last updated 25 August 2025
Other sources
The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigger out-of-bounds write operations.
— Launchpad
Affected Software
3 affected componentsFixes available
Fedoraproject Fedora=25
X.Org libX11<=1.6.3
debian/libx11
2:1.7.2-1+deb11u22:1.8.4-2+deb12u22:1.8.12-1
Remediation
Patch Available
Event History
Dec 13, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:59 PM
DescriptionSeverityWeaknessAffected Software
Feb 19, 2026
Data Sourced
via Ubuntu·06:36 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·06:36 PM
Description
Data Sourced
via Debian·06:36 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2016-7943?
CVE-2016-7943 is a vulnerability in X.org libX11 before 1.6.4 that may allow remote X servers to gain privileges.
2
What is the severity of CVE-2016-7943?
The severity of CVE-2016-7943 is critical with a CVSS score of 9.8.
3
How does CVE-2016-7943 work?
CVE-2016-7943 works by exploiting the XListFonts function in X.org libX11 before 1.6.4, which triggers out-of-bounds write operations.
4
Which software versions are affected by CVE-2016-7943?
CVE-2016-7943 affects libX11 versions before 1.6.4.
5
How can I fix CVE-2016-7943?
To fix CVE-2016-7943, update libX11 to version 1.6.4 or later.