CVE-2026-93543: Out-of-bounds read in libXi's XI2 class parser
Published Sep 24, 2026
·Updated
An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
Affected Software
1 affected component
X.Org libXi<1.8.4
Event History
Sep 24, 2026
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are exposed to this issue?
X clients that use libXi before 1.8.4 and connect to an attacker-controlled or malicious X server are exposed. The described impact is a client crash.
2
What does an attacker need to exploit it?
An attacker needs to operate or control the X server that an affected X client connects to. The vector is network-based, requires no privileges, and requires user interaction.
3
Is confidentiality or integrity impact described?
No. The supplied severity vector identifies no confidentiality or integrity impact; the stated effect is availability impact through crashing the attached X client.