Logo
vulnerabilityCVE-2026-4367
Name
CVE-2026-4367
Source
NVD ( link)Debian ( link)
Description
A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libxpm
Patched

Vulnerability Ratings#


5.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.5.19
Not Affected
buildroot
master
3.5.19
Not Affected
yocto
kirkstone
3.5.17
Not Affected
yocto
master
3.5.19
Not Affected

Resolved with patches#


libxpm (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix CVE-2026-4367: Out-of-bounds read in xpmNextWord()
Olivier Fourdan <ofourdan@redhat.com>
CVE-2026-4367