Executive brief
libXrender is an X Window System library that handles rendering operations for graphical applications. A heap overflow vulnerability in the RenderQueryPictFormats function allows a malicious X server to write beyond allocated memory, potentially enabling code injection into X client processes that connect to it. This could give an attacker complete control over any X applications running on a system.
Technical details
The vulnerability occurs in RenderQueryPictFormats when a malicious X server sends a response with a numSubpixels count greater than numScreens, causing out-of-bounds writes to the screen->subpixel buffer allocated based on the actual screen count. The attack requires a compromised or attacker-controlled X server to which a client connects, enabling arbitrary code execution within the context of the client application.
Affected products
- X.Org Foundation libXrender before 0.9.13
Timeline
- 2026-09-21: disclosed
- 2026-09-18: patched: Fix merged in libXrender repository