CVE-2026-34003Patch

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-15); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-15: 1Mentions · 2026-04-22: 1Mentions · 2026-05-02: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-04-15: 104-1504-2205-02
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-221
Patch1
2026-05-021
Patch1
Full discourse3 posts
  • XLibre@XLibreDev
    Patch

    We released the #XLibre Xserver 25.0.0.22 and 25.1.4 on Apr 21 containing #security fixes for CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, and CVE-2026-34003 of the http://X.Org Server. We recommend everyone update ASAP. #CVE https://github.com/X11Libre/xserver/releases/tag/xlibre-xserver-25.1.4

    Post summary

    The announcement details the release of XLibre Xserver versions with security fixes for five CVEs and urges users to promptly apply the update.

    1029129399.3K
    5.2K followersView on X
  • coffnix@coffnix
    Patch

    Novo LiveCD VIPNIX no AR! Link pra download: https://vipnix.com.br/site/livecd-vipnix/ Correções de bugs do kernel Linux (CVE-2026-31431), correções de bugs do XLibre (CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, and CVE-2026-34003), e correções de bug do driver vmware em virtualbox, corrigindo segfault ao tentar subir o X: https://github.com/coffnix/coffnix-ebuilds/commit/a62c326976eed3ac1b2be169e9787abd4ba39ca8 https://github.com/coffnix/coffnix-ebuilds/commit/fd8acf71442c965476837a9860914b504832768f ZFS atualizado pro branch master pra compilação em kernel 7.0.3: https://github.com/coffnix/coffnix-ebuilds/commit/b84e051cda8df33a30243fec38f407a2ff5766a9 Novo P2Pool 4.15 que trouxe mudanças bem práticas, principalmente com a adição de suporte a I2P, o que melhora bastante a privacidade e a resiliência da rede ao permitir conexões fora do circuito tradicional da internet, além disso adicionaram novos parâmetros de linha de comando para controle de logging, como desativar log em console, arquivo ou completamente, o que dá mais controle em ambientes restritos ou setups mais limpos, especialmente útil pra quem roda node dedicado ou quer reduzir ruído e I/O desnecessário, e também teve um foco grande em estabilidade e manutenção interna, corrigindo problemas como carregamento da lista de peers quando se usa data-dir customizado, leaks de memória no código TCP, ajustes no StratumServer e inconsistências visuais no cálculo de reward, além de vários pequenos hardenings espalhados pelo código, somado a isso atualizaram várias dependências críticas como libuv, curl, BoringSSL, libzmq e RandomX, o que melhora compatibilidade, segurança e desempenho geral sem mudar o comportamento externo de forma agressiva. Também foi atualizado o tema visual. Façam download e se divirtam-se!

    Post summary

    A new LiveCD release is announced that incorporates recent bug fixes for several Linux kernel and XLibre CVEs, with commit links supplied; no exploitation or PoC details are provided.

    321253967
    7.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    http://X.Org X server and Xwayland CVE-2026-34001: XSYNC Use-after-free in miSyncTriggerFence() CVE-2026-34002: XKB Out-of-bounds read in CheckModifierMap() CVE-2026-34003: XKB Buffer overflow in CheckKeyTypes()

    Post summary

    The message provides a brief disclosure of three CVEs affecting the X.Org X server and Xwayland, detailing the type of vulnerability for each.

    00001143
    4.4K followersView on X

Explore more