VYPR
Vypr IntelligenceAI-generatedSep 28, 2026· 6 CVEs

Xorg Libraries: Six Vulnerabilities Including DoS and Client Crashes Disclosed Together

Six vulnerabilities affecting Xorg display server libraries were disclosed on September 28, 2026, with impacts ranging from client crashes to denial of service.

Key findings

  • Six vulnerabilities in Xorg libraries disclosed on September 28, 2026, including one High and five Medium severity flaws.
  • Multiple vulnerabilities stem from out-of-bounds reads in libX11, libXtst, and libXi, potentially crashing X clients.
  • CVE-2026-94287 in libXpm allows local attackers to cause unbounded CPU usage and memory exhaustion.
  • Vulnerabilities affect libXpm before 3.5.19, libXtst before 1.2.6, libX11 before 1.8.14, and libXi before 1.8.4.

On September 28, 2026, a batch of six vulnerabilities affecting the Xorg display server and its associated libraries were disclosed. These vulnerabilities, primarily involving out-of-bounds reads and a denial-of-service flaw, were all published on the same day, indicating a coordinated disclosure event. The most severe of these, CVE-2026-94286, carries a High severity rating, while the others range from Medium to High. These vulnerabilities could be exploited by malicious X servers to crash attached X clients or, in one case, lead to unbounded CPU usage and memory exhaustion.

Several of the vulnerabilities stem from issues within the libX11 library, specifically affecting its byte-oriented codeset parser (CVE-2026-94285), XIM trigger-key registration parser (CVE-2026-94284), and XIM attribute parser (CVE-2026-94283). These three CVEs, all rated Medium, could allow a malicious X server to crash the client. Additionally, libXtst's RECORD reply parser is affected by an out-of-bounds read in CVE-2026-94286, also leading to client crashes.

Another library, libXi, is impacted by CVE-2026-94282, an out-of-bounds read in its XI2 enter/leave/focus cookie conversion, which can similarly cause attached X clients to crash. The remaining vulnerability, CVE-2026-94287, affects libXpm and is a denial of service via an unsigned underflow in its write path. This specific flaw could be exploited by local attackers to cause unbounded CPU usage and memory exhaustion, posing a significant risk to system stability.

The disclosed vulnerabilities affect specific versions of the affected libraries. libXpm is vulnerable before version 3.5.19. libXtst is vulnerable before version 1.2.6. libX11 is vulnerable before version 1.8.14. libXi is vulnerable before version 1.8.4. Users are advised to update to patched versions as soon as possible to mitigate the risks associated with these vulnerabilities.

This coordinated disclosure highlights potential weaknesses in the Xorg ecosystem that could be exploited by adversaries. The prevalence of out-of-bounds read vulnerabilities across multiple core libraries suggests a need for thorough security audits and robust memory management practices within these components. Users of Xorg and its associated libraries should prioritize applying updates to prevent potential system instability and denial-of-service conditions. Further monitoring for any exploitation attempts or related advisories is recommended.

AI-written article. Grounded in 6 CVE records listed below.