CVE-2026-94282
Received Received - Intake

Out-of-Bounds Read in libXi XI2 Cookie Conversion

Vulnerability report for CVE-2026-94282, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: SUSE

Description

An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in libXi's XI2 cookie conversion functions. It occurs when handling enter, leave, or focus events in libXi versions before 1.8.4. A malicious X server could exploit this to read memory outside allocated bounds, potentially crashing an attached X client application.

Detection Guidance

This vulnerability is specific to libXi versions before 1.8.4 and involves an out-of-bounds read in XI2 cookie conversion. Detection requires checking the installed libXi version on your system. Use commands like 'dpkg -l libxi' for Debian-based systems or 'rpm -qa libXi' for RPM-based systems to verify the version.

Impact Analysis

If you use affected X client applications with a malicious X server, this could cause those applications to crash unexpectedly. The impact is limited to local systems since exploitation requires control of the X server. No data theft or privilege escalation is indicated by the CVSS score.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a low-severity out-of-bounds read issue in a client library that could cause crashes but does not involve data exposure or unauthorized access.

Mitigation Strategies

Update libXi to version 1.8.4 or later to address the out-of-bounds read issue in XI2 cookie conversion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94282. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart