Out-of-bounds Read Affecting xorg-server package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.49% (39th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Out-of-bounds Read vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-XORGSERVER-16424105
  • published6 May 2026
  • disclosed5 May 2026
  • creditUnknown

Introduced: 5 May 2026

CVE-2026-34000  (opens in a new tab)
CWE-125  (opens in a new tab)

How to fix?

There is no fixed version for xorg-server.

Overview

Affected versions of this package are vulnerable to Out-of-bounds Read via the CheckSetGeom and XkbAddGeomKeyAlias functions in the geometry processing component. An attacker can access sensitive memory contents or cause the server to crash by sending specially crafted requests to the X11 server.

Workaround

This vulnerability can be mitigated by restricting access to the X11 server. On systems where a graphical environment is not required, consider disabling the X server entirely by setting the default system target to multi-user mode. For systems requiring the X server, ensure that X11 forwarding is disabled in SSH configurations if not explicitly needed, and restrict direct X11 connections to trusted users and networks through firewall rules. If changes are made to SSH configuration, the sshd service must be restarted. If the default system target is changed, a system reboot is required.

CVSS Base Scores

version 4.0
version 3.1