Logo
vulnerabilityCVE-2026-34002
Name
CVE-2026-34002
Source
NVD ( link)Debian ( link)
Description
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can lead to the exposure of sensitive information or cause the server to crash, resulting in a denial of service.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
xserver-xorg
Patched
xwayland
Patched

Vulnerability Ratings#


6.1
CVSSv31
9.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
24.1.13
Not Affected
buildroot
master
24.1.13
Not Affected
yocto
kirkstone
21.1.8
Not Affected
yocto
kirkstone
22.1.8
Not Affected
yocto
master
21.1.24
Not Affected
yocto
master
24.1.13
Not Affected

Resolved with patches#


xserver-xorg (yocto:scarthgap)

#
Title
Author
Resolve
1
xkb: Fix out-of-bounds read in CheckModifierMap()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2026-34002

xwayland (yocto:scarthgap)

#
Title
Author
Resolve
1
xkb: Fix out-of-bounds read in CheckModifierMap()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2026-34002