Integer Underflow (Wraparound) vulnerability in the XKB compatibility map handling of the X.Org X server. The issue occurs in XkbSetCompatMap() when a previously truncated “compat” buffer leaves unused space that is later reused without correctly updating the count of valid entries. This can cause internal size/index calculations to become inconsistent and potentially underflow, resulting in a buffer read overrun when subsequent XKB requests are processed. An attacker with access to the X11 server (local or via remote X11 forwarding/SSH tunneling) can trigger the flaw without user interaction, leading to memory-safety violations and potentially a crash or more severe impact depending on how Xorg/Xwayland is deployed.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:10739 https://access.redhat.com/errata/RHSA-2026:10739
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:11352 https://access.redhat.com/errata/RHSA-2026:11352
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:11369 https://access.redhat.com/errata/RHSA-2026:11369
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:11388 https://access.redhat.com/errata/RHSA-2026:11388
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:11656 https://access.redhat.com/errata/RHSA-2026:11656
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:11692 https://access.redhat.com/errata/RHSA-2026:11692
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:13414 https://access.redhat.com/errata/RHSA-2026:13414
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19125 https://access.redhat.com/errata/RHSA-2026:19125
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19342 https://access.redhat.com/errata/RHSA-2026:19342
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19343 https://access.redhat.com/errata/RHSA-2026:19343
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19344 https://access.redhat.com/errata/RHSA-2026:19344
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:20562 https://access.redhat.com/errata/RHSA-2026:20562
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:20557 https://access.redhat.com/errata/RHSA-2026:20557
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:20547 https://access.redhat.com/errata/RHSA-2026:20547
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:20560 https://access.redhat.com/errata/RHSA-2026:20560
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:20563 https://access.redhat.com/errata/RHSA-2026:20563
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:20561 https://access.redhat.com/errata/RHSA-2026:20561
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:20558 https://access.redhat.com/errata/RHSA-2026:20558
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:20575 https://access.redhat.com/errata/RHSA-2026:20575
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:20590 https://access.redhat.com/errata/RHSA-2026:20590
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:20576 https://access.redhat.com/errata/RHSA-2026:20576
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:20555 https://access.redhat.com/errata/RHSA-2026:20555
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:21699 https://access.redhat.com/errata/RHSA-2026:21699
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:21712 https://access.redhat.com/errata/RHSA-2026:21712
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:21715 https://access.redhat.com/errata/RHSA-2026:21715
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:21716 https://access.redhat.com/errata/RHSA-2026:21716
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:21718 https://access.redhat.com/errata/RHSA-2026:21718
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:21741 https://access.redhat.com/errata/RHSA-2026:21741
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:21742 https://access.redhat.com/errata/RHSA-2026:21742
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:22424 https://access.redhat.com/errata/RHSA-2026:22424
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:22456 https://access.redhat.com/errata/RHSA-2026:22456
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:23254 https://access.redhat.com/errata/RHSA-2026:23254
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:23255 https://access.redhat.com/errata/RHSA-2026:23255
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION Via RHSA-2026:23496 https://access.redhat.com/errata/RHSA-2026:23496
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:24341 https://access.redhat.com/errata/RHSA-2026:24341