Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34000

Опубликовано: 05 мая 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the CheckSetGeom() and XkbAddGeomKeyAlias functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server.

Отчет

This out-of-bounds read vulnerability in the X.Org X server's XKB geometry processing could allow an attacker to leak memory contents or cause a denial of service. Exploitation requires an attacker to establish a connection to the X11 server, either locally or through forwarded remote sessions. Red Hat Enterprise Linux systems with a graphical environment enabled are potentially affected.

Меры по смягчению последствий

To mitigate this vulnerability, restrict access to the X11 server. On systems where a graphical environment is not required, consider disabling the X server entirely by setting the default system target to multi-user mode. For systems requiring the X server, ensure that X11 forwarding is disabled in SSH configurations if not explicitly needed, and restrict direct X11 connections to trusted users and networks through firewall rules. If changes are made to SSH configuration, the sshd service must be restarted. If the default system target is changed, a system reboot is required.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandAffected
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 8tigervncAffected
Red Hat Enterprise Linux 8xorg-x11-serverAffected
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandAffected
Red Hat Enterprise Linux 9xorg-x11-serverAffected
Red Hat Enterprise Linux 9xorg-x11-server-XwaylandAffected
Red Hat Enterprise Linux 10.0 Extended Update Supportxorg-x11-server-XwaylandFixedRHSA-2026:2056326.05.2026
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervncFixedRHSA-2026:2349604.06.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-serverFixedRHSA-2026:2059026.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2451107xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.

EPSS

Процентиль: 39%
0.00489
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
3 месяца назад

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server.

CVSS3: 6.1
nvd
3 месяца назад

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server.

CVSS3: 6.1
debian
3 месяца назад

A flaw was found in the X.Org X server. This out-of-bounds read vulner ...

CVSS3: 6.1
github
3 месяца назад

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server.

CVSS3: 7.8
fstec
4 месяца назад

Уязвимость функции XkbAddGeomKeyAlias() компонента XKB реализации протокола Wayland для X.Org XWaylan и реализации сервера X Window System X.Org Server, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 39%
0.00489
Низкий

6.1 Medium

CVSS3