CVE-2026-94286: Out-of-bounds read in libXtst's RECORD reply parser
Published Sep 28, 2026
·Updated
An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.
Affected Software
1 affected component
X.Org libXtst<1.2.6
Event History
Sep 28, 2026
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are exposed to this issue?
X clients that use libXtst's RECORD functionality and connect to a malicious X server are exposed. The issue affects libXtst versions before 1.2.6.
2
What does an attacker need to exploit it?
An attacker needs to operate or cause a client to connect to a malicious X server that sends a crafted RECORD reply. No privileges on the affected client are required, but user interaction is required according to the supplied vector.
3
What is the practical impact?
A malicious X server can trigger an out-of-bounds read and crash attached X clients. The provided information describes availability impact and does not state that code execution is possible.