← back
CVE-2026-34003

Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access

CVSS 7.8 HIGHEPSS 0.3%CWE-125
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.8EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
23 Apr 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H