VYPR
advisoryPublished Sep 28, 2026· Updated Sep 29, 2026· 1 source

Xorg Libraries: Six Vulnerabilities Including DoS and Client Crashes Disclosed Together

Key findings • Six vulnerabilities in Xorg libraries disclosed on September 28, 2026, including one High and five Medium severity flaws. • Multiple vulnerabilities stem from out-of-bounds rea…

Key findings

  • Six vulnerabilities in Xorg libraries disclosed on September 28, 2026, including one High and five Medium severity flaws.
  • Multiple vulnerabilities stem from out-of-bounds reads in libX11, libXtst, and libXi, potentially crashing X clients.
  • CVE-2026-94287 in libXpm allows local attackers to cause unbounded CPU usage and memory exhaustion.
  • Vulnerabilities affect libXpm before 3.5.19, libXtst before 1.2.6, libX11 before 1.8.14, and libXi before 1.8.4.

On September 28, 2026, a batch of six vulnerabilities affecting the Xorg display server and its associated libraries were disclosed. These vulnerabilities, primarily involving out-of-bounds reads and a denial-of-service flaw, were all published on the same day, indicating a coordinated disclosure event. The most severe of these, CVE-2026-94286, carries a High severity rating, while the others range from Medium to High. These vulnerabilities could be exploited by malicious X servers to crash attached X clients or, in one case, lead to unbounded CPU usage and memory exhaustion.

Several of the vulnerabilities stem from issues within the libX11 library, specifically affecting its byte-oriented codeset parser (CVE-2026-94285), XIM trigger-key registration parser (CVE-2026-94284), and XIM attribute parser (CVE-2026-94283). These three CVEs, all rated Medium, could allow a malicious X server to crash the client. Additionally, libXtst's RECORD reply parser is affected by an out-of-bounds read in CVE-2026-94286, also leading to client crashes.

Another library, libXi, is impacted by CVE-2026-94282, an out-of-bounds read in its XI2 enter/leave/focus cookie conversion, which can similarly cause attached X clients to crash. The remaining vulnerability, CVE-2026-94287, affects libXpm and is a denial of service via an unsigned underflow in its write path. This specific flaw could be exploited by local attackers to cause unbounded CPU usage and memory exhaustion, posing a significant risk to system stability.

The disclosed vulnerabilities affect specific versions of the affected libraries. libXpm is vulnerable before version 3.5.19. libXtst is vulnerable before version 1.2.6. libX11 is vulnerable before version 1.8.14. libXi is vulnerable before version 1.8.4. Users are advised to update to patched versions as soon as possible to mitigate the risks associated with these vulnerabilities.

This coordinated disclosure highlights potential weaknesses in the Xorg ecosystem that could be exploited by adversaries. The prevalence of out-of-bounds read vulnerabilities across multiple core libraries suggests a need for thorough security audits and robust memory management practices within these components. Users of Xorg and its associated libraries should prioritize applying updates to prevent potential system instability and denial-of-service conditions. Further monitoring for any exploitation attempts or related advisories is recommended.

Synthesized by Vypr AI