MalwareObserver[verified]@MalwareObserverDisclosure
A new vulnerability (CVE-2026-4367) affecting libXpm has been disclosed, with a reference to Red Hat errata for further information.
Open Source Security mailing list@oss_securityDisclosure
The advisory announces CVE-2026-4367, detailing an out‑of‑bounds read in libXpm triggered by malformed XPM files; no PoC, exploit, active exploitation, or patch information is disclosed.
Ferramentas Linux@Cezar_H_LinuxPatch
The post announces that CVE-2026-4367 in libXpm is fixed and provides an auto‑update script along with iptables/AppArmor mitigation for those unable to apply the patch, linking to further guidance.
CVE@CVEnewDisclosure
The text announces a local privilege vulnerability in libXpm’s `xpmNextWord()` function, describing it as an out-of-bounds read.
Joel B.D.@darkshramPatch
The post announces that LibXpm 3.5.19 released in ALDOS patches CVE‑2026‑4367.