CVE-2026-34000: Xwayland: xorg: x.org x server: information disclosure and denial of service via out-of-bounds read in xkb geometry processing.

Published Mar 25, 2026
·
Updated

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the CheckSetGeom() and XkbAddGeomKeyAlias functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server.

Other sources

Out-of-bounds Read vulnerability in the XKB geometry processing of the X.Org X server. The issue is located in CheckSetGeom(), where bounds checking is performed using only the first key name of each alias entry (alias vs. real key name). Because the second name is not properly validated, XkbAddGeomKeyAlias may read uninitialized or out-of-bounds memory when processing a crafted request. An attacker who can connect to the X11 server (locally or via forwarded remote sessions) can trigger this without user interaction, potentially leaking memory contents and/or causing a crash.

Red Hat

Affected Software

8 affected components
X.Org X.Org X Server
X.Org Xwayland
X.Org X Server
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0

Event History

Mar 25, 2026
Data Sourced
via Red Hat·06:38 AM
DescriptionSeverityAffected Software
May 5, 2026
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-34000?

CVE-2026-34000 has a high severity level due to its potential for information disclosure and denial of service.

2

How do I fix CVE-2026-34000?

To fix CVE-2026-34000, update to the latest version of the X.Org X server or Xwayland that addresses this vulnerability.

3

What software is affected by CVE-2026-34000?

CVE-2026-34000 affects the X.Org X server and Xwayland on various versions of Red Hat Enterprise Linux.

4

What impact does CVE-2026-34000 have on systems?

CVE-2026-34000 can lead to information disclosure and a denial of service, impacting system stability and data security.

5

Is there a workaround for CVE-2026-34000 before applying a patch?

There are no recommended workarounds for CVE-2026-34000; applying security patches is the best approach.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203