Out-of-Bounds Read Vulnerability in X.Org X Server Affecting Red Hat
CVE-2026-34002
6.1MEDIUM
What is CVE-2026-34002?
A flaw has been identified in the X.Org X server that pertains to its handling of the XKB (X Keyboard Extension) modifier map. This out-of-bounds read vulnerability allows an attacker with access to the X11 server to exploit the system by sending a specially crafted request. Such an exploit can lead to the server reading beyond its intended memory limits, which can expose sensitive information or potentially crash the server, causing a denial of service. It is essential for users to ensure their systems are updated to mitigate any risks associated with this vulnerability.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Jan-Niklas Sohn (TrendAI Zero Day Initiative) for reporting this issue.