Bug 2448984 (CVE-2026-4367) - CVE-2026-4367 libXpm: libXpm: Denial of Service via out-of-bounds read in XPM file parsing
Summary: CVE-2026-4367 libXpm: libXpm: Denial of Service via out-of-bounds read in XPM...
Keywords:
Status: NEW
Alias: CVE-2026-4367
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-19 10:12 UTC by OSIDB Bzimport
Modified: 2026-06-16 16:41 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-03-19 10:12:07 UTC
An Out-of-Bounds Read vulnerability exists in the xpmNextWord() function of the libXpm library. The issue is caused by improper validation of file boundaries when parsing XPM image data. When a specially crafted or very small XPM file is processed, the internal pointer may advance beyond the actual end of the file, resulting in an out-of-bounds memory read. This can lead to application crashes and denial-of-service conditions in applications that rely on libXpm. The vulnerability requires local access and low privileges, and does not impact confidentiality or integrity.


Note You need to log in before you can comment on or make changes to this bug.