CVE-2026-88806: libX11 XkbGetMap Reply Heap-based Buffer Overflow
Published Sep 21, 2026
·Updated
A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the keysymmap.
Affected Software
1 affected component
libX11<1.8.14
Event History
Sep 21, 2026
CVE Published
via MITRE·01:42 PM
Data Sourced
via MITRE·01:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are exposed?
Systems using libX11 versions earlier than 1.8.14 may be exposed when they connect to a malicious X server. The issue affects processing of an XkbGetMap reply from that server.
2
What does exploitation require?
An attacker must control or operate a malicious X server that the affected client connects to. The CVSS vector also indicates user interaction is required.
3
How can I determine whether an installation is affected?
Check the installed libX11 version. Versions before 1.8.14 are affected according to the available information.