CVE-2026-34002General(redhat / enterprise_linux)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can lead to the exposure of sensitive information or cause the server to crash, resulting in a denial of service.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-805

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • x_server

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 5 classified signals
  • Peaked 6d ago at 1 mentions (2026-04-15); latest day: 1
  • 7 total mentions across 7 days

Affected systems

Products
enterprise_linuxx_server

6 versions affected across 2 products

Deep dive

Activity timeline7 mentions / 7d
00111Mentions · 2026-04-15: 1Mentions · 2026-04-22: 1Mentions · 2026-05-02: 1Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Mentions · 2026-05-16: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-04-15: 1Technical Details · 2026-05-02: 104-1504-2205-0205-1305-1405-1505-16
Signal classification2 categories
General
571.4%
Patch
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-151
General1
2026-04-221
Patch1
2026-05-021
Patch1
2026-05-131
General1
2026-05-141
General1
2026-05-151
General1
2026-05-161
General1
Full discourse7 posts
  • XLibre@XLibreDev
    Patch

    We released the #XLibre Xserver 25.0.0.22 and 25.1.4 on Apr 21 containing #security fixes for CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, and CVE-2026-34003 of the http://X.Org Server. We recommend everyone update ASAP. #CVE https://github.com/X11Libre/xserver/releases/tag/xlibre-xserver-25.1.4

    Post summary

    The post announces a new XLibre Xserver release that includes security fixes for five CVEs and urges users to update immediately to mitigate the risks.

    1029129399.3K
    5.2K followersView on X
  • coffnix@coffnix
    Patch

    Novo LiveCD VIPNIX no AR! Link pra download: https://vipnix.com.br/site/livecd-vipnix/ Correções de bugs do kernel Linux (CVE-2026-31431), correções de bugs do XLibre (CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, and CVE-2026-34003), e correções de bug do driver vmware em virtualbox, corrigindo segfault ao tentar subir o X: https://github.com/coffnix/coffnix-ebuilds/commit/a62c326976eed3ac1b2be169e9787abd4ba39ca8 https://github.com/coffnix/coffnix-ebuilds/commit/fd8acf71442c965476837a9860914b504832768f ZFS atualizado pro branch master pra compilação em kernel 7.0.3: https://github.com/coffnix/coffnix-ebuilds/commit/b84e051cda8df33a30243fec38f407a2ff5766a9 Novo P2Pool 4.15 que trouxe mudanças bem práticas, principalmente com a adição de suporte a I2P, o que melhora bastante a privacidade e a resiliência da rede ao permitir conexões fora do circuito tradicional da internet, além disso adicionaram novos parâmetros de linha de comando para controle de logging, como desativar log em console, arquivo ou completamente, o que dá mais controle em ambientes restritos ou setups mais limpos, especialmente útil pra quem roda node dedicado ou quer reduzir ruído e I/O desnecessário, e também teve um foco grande em estabilidade e manutenção interna, corrigindo problemas como carregamento da lista de peers quando se usa data-dir customizado, leaks de memória no código TCP, ajustes no StratumServer e inconsistências visuais no cálculo de reward, além de vários pequenos hardenings espalhados pelo código, somado a isso atualizaram várias dependências críticas como libuv, curl, BoringSSL, libzmq e RandomX, o que melhora compatibilidade, segurança e desempenho geral sem mudar o comportamento externo de forma agressiva. Também foi atualizado o tema visual. Façam download e se divirtam-se!

    Post summary

    The post announces a LiveCD with kernel and application bug fixes, providing direct patch links, but offers no evidence of exploitation or PoC.

    321253967
    7.6K followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 65% of vulnerabilities from past week, CVE-2026-34002 has 17 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post highlights that CVE-2026-34002 has a high volume of articles but offers no concrete technical, exploitation, or patch details.

    0001080
    71 followersView on X
  • Open Source Security mailing list@oss_security
    General

    http://X.Org X server and Xwayland CVE-2026-34001: XSYNC Use-after-free in miSyncTriggerFence() CVE-2026-34002: XKB Out-of-bounds read in CheckModifierMap() CVE-2026-34003: XKB Buffer overflow in CheckKeyTypes()

    Post summary

    It enumerates three CVEs for X.Org X server and XWayland, specifying their vulnerability types but offering no PoC, exploits, patches, or evidence of real‑world attacks.

    00001143
    4.4K followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 54% of vulnerabilities from past week, CVE-2026-34002 has 16 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The tweet highlights the popularity of CVE-2026-34002 in media but provides no technical, exploit, or mitigation details.

    0000048
    71 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 42% of vulnerabilities from past week, CVE-2026-34002 has 18 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post highlights the high article count for CVE-2026-34002 but offers no technical, exploit, patch, or threat-related details.

    0000045
    71 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 31% of vulnerabilities from past week, CVE-2026-34002 has 18 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post indicates that CVE-2026-34002 has attracted significant media attention, citing 18 articles, but it does not provide any technical details, PoC, exploit code, or evidence of exploitation.

    0000049
    71 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appx.orgx_server---

Explore more