Junglewise Threat Intelligence

CVE-2026-34002: X.Org X Server out-of-bounds read in XKB modifier map handling

CVE-2026-34002 · Severity: medium · CVSS 6.1 · Published 2026-05-05

Technologies: Red Hat Enterprise Linux. Vendors: X.Org, Red Hat.

Executive brief

A security vulnerability has been identified in the X.Org X Server, a fundamental component used to display graphical user interfaces on Linux and Unix-like operating systems. An attacker with access to the system can trigger a memory error that may allow them to view sensitive information or cause the graphical interface to crash. This could lead to a disruption of services or the unauthorized exposure of data handled by the display server.

Technical details

An out-of-bounds read vulnerability exists in the X.Org X server (including Xwayland) within the X Keyboard Extension (XKB) modifier map handling. The flaw is triggered when the server processes a malformed request related to modifier maps, leading to a buffer access with an incorrect length value (CWE-805). An attacker with access to the X11 server can exploit this to read sensitive memory contents or cause a server crash. While Red Hat assesses this as a local attack vector with medium severity (CVSS 6.1), NVD notes potential network reachability depending on server configuration. Patches have been released by major distributions including Red Hat (RHSA-2026:20547, RHSA-2026:20555).

Affected products

  • X.Org X Server All versions prior to May 2026 patches
  • X.Org Xwayland All versions prior to May 2026 patches
  • Red Hat Enterprise Linux 6.0, 7.0, 8.0, 9.0, 10.0

Timeline

  • 2026-05-05: disclosed: Initial disclosure and CVE assignment
  • 2026-05-05: advisory: NVD published the vulnerability details
  • 2026-05-26: patched: Red Hat released security updates for various RHEL versions

References