An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client. | |
| Title | Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing | |
| First Time appeared |
X.org
X.org libxi |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:* | |
| Vendors & Products |
X.org
X.org libxi |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-09-24T17:16:35.659Z
Reserved: 2026-09-18T09:08:10.295Z
Link: CVE-2026-93544
No data.
Status : Received
Published: 2026-09-24T17:17:10.430
Modified: 2026-09-24T17:17:10.430
Link: CVE-2026-93544
No data.
OpenCVE Enrichment
No data.
Weaknesses