Logo
vulnerabilityCVE-2026-34003
Name
CVE-2026-34003
Source
NVD ( link)Debian ( link)
Description
A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
xserver-xorg
Patched

Vulnerability Ratings#


7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
21.1.8
Not Affected
yocto
master
21.1.23
Not Affected

Resolved with patches#


xserver-xorg (yocto:scarthgap)

#
Title
Author
Resolve
1
xkb: Add more _XkbCheckRequestBounds()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2026-34003
2
xkb: Add additional bound checking in CheckKeyTypes()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2026-34003