Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34003

Опубликовано: 23 апр. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.

Отчет

An Important out-of-bounds memory access vulnerability exists in the X.Org X server's XKB key types request validation. This flaw could lead to information exposure or a server crash and requires a specially crafted request to trigger. Systems running a graphical environment are potentially affected, with higher impact outcomes possible in certain configurations.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2026:1135228.04.2026
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2026:1912519.05.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportxorg-x11-server-XwaylandFixedRHSA-2026:2056326.05.2026
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervncFixedRHSA-2026:2349604.06.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-serverFixedRHSA-2026:2059026.05.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupporttigervncFixedRHSA-2026:2245602.06.2026
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2026:1165629.04.2026
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2026:1169229.04.2026
Red Hat Enterprise Linux 8tigervncFixedRHSA-2026:1341404.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2451113xorg: xwayland: X.Org X server: Information exposure and denial of service via out-of-bounds memory access

EPSS

Процентиль: 16%
0.0025
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.

CVSS3: 7.8
nvd
3 месяца назад

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.

CVSS3: 7.1
msrc
3 месяца назад

Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access

CVSS3: 7.8
debian
3 месяца назад

A flaw was found in the X.Org X server's XKB key types request validat ...

CVSS3: 7.8
github
3 месяца назад

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.

EPSS

Процентиль: 16%
0.0025
Низкий

7.8 High

CVSS3