Out-of-bounds memory access vulnerability in the XKB key types request validation of the X.Org X server. The function CheckKeyTypes() loops over elements derived from the client’s request but does not perform adequate bounds checking to guarantee that subsequent reads remain within the request payload. A specially crafted request can cause CheckKeyTypes() to read uninitialized memory past the end of the request data, potentially leading to information exposure and/or a server crash. In certain configurations (as indicated by the submitted impact notes), this memory-safety flaw may be exploitable for higher impact outcomes.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:10739 https://access.redhat.com/errata/RHSA-2026:10739
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:11352 https://access.redhat.com/errata/RHSA-2026:11352
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:11369 https://access.redhat.com/errata/RHSA-2026:11369
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:11388 https://access.redhat.com/errata/RHSA-2026:11388
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:11656 https://access.redhat.com/errata/RHSA-2026:11656
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:11692 https://access.redhat.com/errata/RHSA-2026:11692
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:13414 https://access.redhat.com/errata/RHSA-2026:13414