CVE-2026-34002 Details
Description
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can lead to the exposure of sensitive information or cause the server to crash, resulting in a denial of service.
A vulnerability allowing out-of-bounds read has been identified in the X.Org X server, specifically in the handling of the XKB (X Keyboard Extension) modifier map. This flaw arises because the CheckModifierMap() function processes data without properly validating the length of the client request. Consequently, an attacker with access to the X11 server can exploit this vulnerability by sending a malformed request that causes the server to read beyond its intended memory boundaries. This exploitation can lead to the exposure of sensitive information from memory or cause the server to crash, resulting in a denial-of-service condition.
To mitigate this vulnerability, restrict access to the X11 server. If the X.Org X server is not needed, consider disabling or uninstalling it. For systems that require the X server, limit access to trusted users and networks, which can be done by configuring 'xhost' or using firewall rules to control connections to the X server. Note that changes to the X server configuration or service may require a restart of the X server, impacting active graphical sessions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-805 | Buffer Access with Incorrect Length Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| x.org x server | All versions |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
18 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | CVE Modified | [email protected] |
| Jun 5, 2026 | CVE Modified | [email protected] |
| Jun 4, 2026 | CVE Modified | [email protected] |
| Jun 4, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 7, 2026 | Initial Analysis | [email protected] |
| May 5, 2026 | New CVE Received | [email protected] |