Out-of-Bounds Memory Access in X.Org X Server Affects Red Hat Products
CVE-2026-34003
7.8HIGH
What is CVE-2026-34003?
A flaw has been identified in X.Org X server's validation of XKB key types requests. This vulnerability allows a local attacker to craft specific requests that exploit memory access vulnerabilities, potentially leading to the exposure of sensitive information or causing the X server to crash, resulting in a Denial of Service (DoS). Under certain configurations, the impact could be even more severe, making this a significant concern for systems relying on X.Org X Server for graphical interfaces.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Jan-Niklas Sohn (TrendAI Zero Day Initiative) for reporting this issue.