CVE-2026-4367Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 1 mentions (2026-04-22); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-24: 1Mentions · 2026-04-28: 1Mentions · 2026-06-16: 1Mentions · 2026-06-26: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-28: 1Technical Details · 2026-06-16: 104-2204-2404-2806-1606-26
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-04-241
Patch1
2026-04-281
Disclosure1
2026-06-161
Disclosure1
2026-06-261
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    http://X.Org Security Advisory: CVE-2026-4367: libXpm Out-of-bounds read in xpmNextWord() https://www.openwall.com/lists/oss-security/2026/04/21/3 A small XPM file with a malformed color table definition may cause out-of-bound read

    Post summary

    The advisory announces CVE-2026-4367, detailing an out‑of‑bounds read in libXpm triggered by malformed XPM files; no PoC, exploit, active exploitation, or patch information is disclosed.

    00030267
    4.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Linux security: CVE-2026-4367 in libXpm is fixed, but image parsing bugs never die. Here's how to check, auto-update (bash script), and mitigate with iptables/AppArmor – works TODAY even if you can't patch. Read more -> https://tinyurl.com/mr3bfdtv #openSUSE https://t.co/SDSdKqN4ur

    Post summary

    The post announces that CVE-2026-4367 in libXpm is fixed and provides an auto‑update script along with iptables/AppArmor mitigation for those unable to apply the patch, linking to further guidance.

    1000062
    1.5K followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-4367](https://access.redhat.com/errata/RHSA-2026:30354) A flaw was found in libXpm. A l... https://access.redhat.com/errata/RHSA-2026:30354 #Vulnerability #CVE #ZeroDay

    Post summary

    A new vulnerability (CVE-2026-4367) affecting libXpm has been disclosed, with a reference to Red Hat errata for further information.

    0000048
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4367 A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially… https://www.cve.org/CVERecord?id=CVE-2026-4367

    Post summary

    The text announces a local privilege vulnerability in libXpm’s `xpmNextWord()` function, describing it as an out-of-bounds read.

    00000125
    57.6K followersView on X
  • Joel B.D.@darkshram
    Patch

    Disponible LibXpm 3.5.19 en ALDOS, corrigiendo vulnerabilidad CVE-2026-4367 vía @darkshram https://www.alcancelibre.org/noticias/disponible-libxpm-3-5-19-en-aldos-corrigiendo-vulnerabilidad-cve-2026-4367

    Post summary

    The post announces that LibXpm 3.5.19 released in ALDOS patches CVE‑2026‑4367.

    0000091
    1.0K followersView on X

Explore more