Out-of-Bounds Read Vulnerability in libXi Affecting FreeDesktop
CVE-2026-93541

6.5MEDIUM

Key Information:

Vendor

X.org

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-93541?

An out-of-bounds read vulnerability was discovered in libXi's XQueryDeviceState() function. This flaw may allow attackers to exploit the system by reading portions of memory outside the intended boundaries, potentially leading to unintended information disclosure. Users are advised to update to libXi version 1.8.4 or later to mitigate risks associated with this vulnerability.

Affected Version(s)

libXi 0 < 1.8.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AISLE in partnership with Red Hat
.