CVE-2026-94284: Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parser
Published Sep 28, 2026
·Updated
An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Affected Software
1 affected component
X.Org libX11<1.8.14
Event History
Sep 28, 2026
CVE Published
via MITRE·08:42 AM
Data Sourced
via MITRE·08:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are exposed to this issue?
X clients using libX11 versions before 1.8.14 are exposed when they connect to a malicious X server.
2
What does exploitation require?
An attacker needs to operate or otherwise cause a client to connect to a malicious X server. The user must interact with the client, as reflected by the UI:R vector.
3
What is the likely impact?
A malicious X server can trigger an out-of-bounds read in the XIM trigger-key registration parser and crash attached X clients. The provided vector indicates availability impact only, with no confidentiality or integrity impact.