CVE-2026-34000Patch(redhat / enterprise_linux)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or remotely, can exploit this without user interaction. This could lead to the disclosure of memory contents or cause a denial of service by crashing the server.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • x_server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-15); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
enterprise_linuxx_server

6 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-15: 1Mentions · 2026-04-22: 1Mentions · 2026-05-02: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-04-15: 1Technical Details · 2026-05-02: 104-1504-2205-02
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-221
Patch1
2026-05-021
Patch1
Full discourse3 posts
  • XLibre@XLibreDev
    Patch

    We released the #XLibre Xserver 25.0.0.22 and 25.1.4 on Apr 21 containing #security fixes for CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, and CVE-2026-34003 of the http://X.Org Server. We recommend everyone update ASAP. #CVE https://github.com/X11Libre/xserver/releases/tag/xlibre-xserver-25.1.4

    Post summary

    The post announces new XLibre Xserver releases that patch multiple CVEs and urges users to apply the update promptly.

    1029129399.3K
    5.2K followersView on X
  • coffnix@coffnix
    Patch

    Novo LiveCD VIPNIX no AR! Link pra download: https://vipnix.com.br/site/livecd-vipnix/ Correções de bugs do kernel Linux (CVE-2026-31431), correções de bugs do XLibre (CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, and CVE-2026-34003), e correções de bug do driver vmware em virtualbox, corrigindo segfault ao tentar subir o X: https://github.com/coffnix/coffnix-ebuilds/commit/a62c326976eed3ac1b2be169e9787abd4ba39ca8 https://github.com/coffnix/coffnix-ebuilds/commit/fd8acf71442c965476837a9860914b504832768f ZFS atualizado pro branch master pra compilação em kernel 7.0.3: https://github.com/coffnix/coffnix-ebuilds/commit/b84e051cda8df33a30243fec38f407a2ff5766a9 Novo P2Pool 4.15 que trouxe mudanças bem práticas, principalmente com a adição de suporte a I2P, o que melhora bastante a privacidade e a resiliência da rede ao permitir conexões fora do circuito tradicional da internet, além disso adicionaram novos parâmetros de linha de comando para controle de logging, como desativar log em console, arquivo ou completamente, o que dá mais controle em ambientes restritos ou setups mais limpos, especialmente útil pra quem roda node dedicado ou quer reduzir ruído e I/O desnecessário, e também teve um foco grande em estabilidade e manutenção interna, corrigindo problemas como carregamento da lista de peers quando se usa data-dir customizado, leaks de memória no código TCP, ajustes no StratumServer e inconsistências visuais no cálculo de reward, além de vários pequenos hardenings espalhados pelo código, somado a isso atualizaram várias dependências críticas como libuv, curl, BoringSSL, libzmq e RandomX, o que melhora compatibilidade, segurança e desempenho geral sem mudar o comportamento externo de forma agressiva. Também foi atualizado o tema visual. Façam download e se divirtam-se!

    Post summary

    The post announces a new LiveCD release that includes patches for several recent CVEs, providing commit URLs and noting bug fixes such as a VMware‑related segfault.

    321253967
    7.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    5 CVEs in http://X.Org X server prior to 21.1.22 and Xwayland prior to 24.1.10 https://www.openwall.com/lists/oss-security/2026/04/14/8 CVE-2026-33999: XKB Integer Underflow in XkbSetCompatMap() CVE-2026-34000: XKB Out-of-bounds Read in CheckSetGeom() + next tweet

    Post summary

    The text announces five CVEs affecting the X.Org X server and Xwayland and provides limited technical details on two of the vulnerabilities.

    10041250
    4.6K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appx.orgx_server---

Explore more