CVE-2026-33999Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other severe impacts.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-191

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-15); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-15: 1Mentions · 2026-04-22: 1Mentions · 2026-05-02: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-04-15: 1Technical Details · 2026-05-02: 104-1504-2205-02
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-221
Patch1
2026-05-021
Disclosure1
Full discourse3 posts
  • XLibre@XLibreDev
    Patch

    We released the #XLibre Xserver 25.0.0.22 and 25.1.4 on Apr 21 containing #security fixes for CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, and CVE-2026-34003 of the http://X.Org Server. We recommend everyone update ASAP. #CVE https://github.com/X11Libre/xserver/releases/tag/xlibre-xserver-25.1.4

    Post summary

    XLibre released Xserver updates that address five CVE‑2026‑33999 to CVE‑2026‑34003, urging users to update immediately.

    1029129399.3K
    5.2K followersView on X
  • coffnix@coffnix
    Disclosure

    Novo LiveCD VIPNIX no AR! Link pra download: https://vipnix.com.br/site/livecd-vipnix/ Correções de bugs do kernel Linux (CVE-2026-31431), correções de bugs do XLibre (CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, and CVE-2026-34003), e correções de bug do driver vmware em virtualbox, corrigindo segfault ao tentar subir o X: https://github.com/coffnix/coffnix-ebuilds/commit/a62c326976eed3ac1b2be169e9787abd4ba39ca8 https://github.com/coffnix/coffnix-ebuilds/commit/fd8acf71442c965476837a9860914b504832768f ZFS atualizado pro branch master pra compilação em kernel 7.0.3: https://github.com/coffnix/coffnix-ebuilds/commit/b84e051cda8df33a30243fec38f407a2ff5766a9 Novo P2Pool 4.15 que trouxe mudanças bem práticas, principalmente com a adição de suporte a I2P, o que melhora bastante a privacidade e a resiliência da rede ao permitir conexões fora do circuito tradicional da internet, além disso adicionaram novos parâmetros de linha de comando para controle de logging, como desativar log em console, arquivo ou completamente, o que dá mais controle em ambientes restritos ou setups mais limpos, especialmente útil pra quem roda node dedicado ou quer reduzir ruído e I/O desnecessário, e também teve um foco grande em estabilidade e manutenção interna, corrigindo problemas como carregamento da lista de peers quando se usa data-dir customizado, leaks de memória no código TCP, ajustes no StratumServer e inconsistências visuais no cálculo de reward, além de vários pequenos hardenings espalhados pelo código, somado a isso atualizaram várias dependências críticas como libuv, curl, BoringSSL, libzmq e RandomX, o que melhora compatibilidade, segurança e desempenho geral sem mudar o comportamento externo de forma agressiva. Também foi atualizado o tema visual. Façam download e se divirtam-se!

    Post summary

    Novo LiveCD VIPNIX releases a new edition, highlighting kernel and component patches for several CVEs and providing GitHub links to the corresponding fixes.

    321253967
    7.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    5 CVEs in http://X.Org X server prior to 21.1.22 and Xwayland prior to 24.1.10 https://www.openwall.com/lists/oss-security/2026/04/14/8 CVE-2026-33999: XKB Integer Underflow in XkbSetCompatMap() CVE-2026-34000: XKB Out-of-bounds Read in CheckSetGeom() + next tweet

    Post summary

    The message announces five CVEs affecting the X.Org X server and Xwayland, providing technical details of two specific vulnerabilities but no PoC, exploit code, patch, or evidence of active exploitation.

    10041250
    4.6K followersView on X

Explore more