Bug 2539102 - CVE-2026-88806 libX11: libX11: Heap-based buffer overflow via malicious X server [fedora-all]
Summary: CVE-2026-88806 libX11: libX11: Heap-based buffer overflow via malicious X ser...
Keywords:
Status: MODIFIED
Alias: None
Product: Fedora
Classification: Fedora
Component: libX11
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Adam Jackson
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["5f35e1af-d880-4248-b702-3...
Depends On:
Blocks: CVE-2026-88806
TreeView+ depends on / blocked
 
Reported: 2026-09-23 07:31 UTC by Vladimir Vasilev
Modified: 2026-09-30 09:45 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Vladimir Vasilev 2026-09-23 07:31:44 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.

Comment 1 Fedora Update System 2026-09-30 09:45:36 UTC
FEDORA-2026-0072911d9d (libX11-1.8.13-3.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-0072911d9d


Note You need to log in before you can comment on or make changes to this bug.