Description
A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.
Problem types
Product status
Timeline
| 2026-03-25: | Reported to Red Hat. |
| 2026-04-23: | Made public. |
Credits
Red Hat would like to thank Jan-Niklas Sohn (TrendAI Zero Day Initiative) for reporting this issue.
References
access.redhat.com/security/cve/CVE-2026-34003
bugzilla.redhat.com/show_bug.cgi?id=2451113 (RHBZ#2451113)