CVE-2026-88806 PUBLISHED

libX11 XkbGetMap Reply Heap-based Buffer Overflow

Assigner: suse
Reserved: 10.09.2026 Published: 21.09.2026 Updated: 21.09.2026

A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.5

Product Status

Vendor x.org
Product libX11
Versions Default: unaffected
  • affected from 0 to 1.8.14 (excl.)

Credits

  • Adam Bedard working with TrendAI Zero Day Initiative finder
  • Claude:claude-opus-4-6 tool

References

Problem Types

  • CWE-122 Heap-based buffer overflow CWE

Impacts

  • CAPEC-242 Code Injection