CVE-2026-93545: Out-of-bounds read in libXi's XListInputDevices()
Published Sep 24, 2026
·Updated
An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
Affected Software
1 affected component
X.Org libXi<1.8.4
Event History
Sep 24, 2026
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are exposed to this issue?
X clients linked against libXi versions before 1.8.4 are exposed when they connect to a malicious X server. The reported impact is a crash of the attached client.
2
What does an attacker need to exploit it?
An attacker needs to operate or control an X server that the target client connects to. Exploitation also requires the client user to interact with or connect to that server.
3
Is this a confidentiality or integrity issue?
The available information describes an out-of-bounds read that can crash the client, resulting in an availability impact. No confidentiality or integrity impact is reported.