CVE-2026-94282: Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion
Published Sep 28, 2026
·Updated
An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.
Affected Software
1 affected component
X.Org libXi<1.8.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libXito a version that resolves this vulnerability.Fixed in 1.8.4
Event History
Sep 28, 2026
CVE Published
via MITRE·08:18 AM
Data Sourced
via MITRE·08:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Sep 29, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are exposed to this issue?
X clients that use libXi before 1.8.4 and connect to an untrusted or malicious X server are exposed. The described impact is a crash of the attached X client.
2
What does an attacker need to exploit it?
An attacker needs to operate or control the X server to which the affected client connects. The vector is local and requires low privileges and user interaction, according to the supplied severity vector.
3
What version resolves the issue?
Upgrade libXi to version 1.8.4 or later. The issue affects versions before 1.8.4.