CVE-2026-94283: Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser
An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Affected Software
Event History
Frequently Asked Questions
Which systems and applications are exposed?
X clients that use libX11 versions before 1.8.14 and connect to an X server are exposed. The issue is in XIM attribute parsing, and the documented impact is a client crash.
What must an attacker control to trigger the issue?
An attacker needs to operate or control a malicious X server that an affected X client connects to. The supplied data does not indicate that the issue can be triggered by an ordinary untrusted application alone.
Is user interaction required?
Yes. The vector specifies user interaction, which is consistent with an affected client needing to attach to the malicious X server.
What is the available remediation?
Upgrade libX11 to version 1.8.14 or later. The vulnerability affects versions before 1.8.14.