CVE-2026-88807 PUBLISHED

libXrender RenderQueryPictFormats Reply Heap-based Buffer Overflow

Assigner: suse
Reserved: 10.09.2026 Published: 21.09.2026 Updated: 21.09.2026

A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 8.9

Product Status

Vendor X.org
Product libXrender
Versions Default: unaffected
  • affected from 0 to 0.9.13 (excl.)

Credits

  • Adam Bedard working with TrendAI Zero Day Initiative finder
  • Claude:claude-opus-4-6 tool

References

Problem Types

  • CWE-122 Heap-based buffer overflow CWE

Impacts

  • CAPEC-242 Code Injection