CVE-2026-93544: Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing
An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.
Affected Software
Event History
Frequently Asked Questions
Which clients are exposed to this issue?
X clients using libXi versions before 1.8.4 that process XI2 XIQueryDevice replies from an X server are exposed. The server can be malicious.
What does an attacker need to do to exploit it?
An attacker needs to operate or control an X server that an affected client connects to, then send a crafted XI2 XIQueryDevice reply. No client privileges are required, but user interaction is required for the client to connect to that server.
What is the expected impact?
The documented impact is a crash of the attached X client, resulting in denial of service. No confidentiality or integrity impact is stated.
How can the issue be remediated?
Update libXi to version 1.8.4 or later. The issue affects versions before 1.8.4.