Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4367

Опубликовано: 21 апр. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the xpmNextWord() function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

Отчет

The vulnerability is assessed as Medium severity due to its impact being limited to availability. While exploitation requires local access and low privileges, it does not require user interaction. Successful exploitation can cause applications processing XPM files to crash, which may affect batch processing systems or graphical applications. The absence of confidentiality and integrity impact reduces the overall severity, but the ease of triggering the issue still presents a reliability concern.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libXpmFix deferred
Red Hat Enterprise Linux 6libXpmFix deferred
Red Hat Enterprise Linux 7libXpmFix deferred
Red Hat Enterprise Linux 8libXpmFix deferred
Red Hat Enterprise Linux 9libXpmFix deferred
Red Hat Hardened Imageslibxpm-main-3.5.17-7.2.hum1FixedRHSA-2026:3035426.06.2026
Red Hat Hardened Imageslibxpm-main-3.5.19-4.hum1FixedRHSA-2026:4707228.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2448984libXpm: libXpm: Denial of Service via out-of-bounds read in XPM file parsing

EPSS

Процентиль: 3%
0.00129
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

CVSS3: 5.5
nvd
около 2 месяцев назад

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

CVSS3: 5.5
msrc
около 1 месяца назад

Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing

CVSS3: 5.5
debian
около 2 месяцев назад

A flaw was found in libXpm. A local user with low privileges could exp ...

suse-cvrf
около 2 месяцев назад

Security update for libXpm

EPSS

Процентиль: 3%
0.00129
Низкий

5.5 Medium

CVSS3