CVE-2026-93524
Public on 2026-10-09
Modified on 2026-10-09
Description
CheckKeySyms() in xkb/xkb.c populates a symsPerKey[] validation array with new key widths for keys in the SetMap request range, then continues filling entries for keys beyond the range. However, the second loop starts at index i = nKeySyms (the first loop's counter) rather than i = firstKeySym + nKeySyms. When firstKeySym is large and nKeySyms is small, the second loop overwrites symsPerKey[target] with the old width from the existing map.
CheckKeyActions() then validates the wire action count against the stale old width and accepts it. In _XkbSetMap(), SetKeySyms() widens the key (resizing actions to nGroups * newWidth), but SetKeyActions() then resizes again to the old count. A subsequent XkbGetMap request reads XkbKeyNumActions() entries (derived from the new wider key_sym_map.width) from the shorter action allocation, causing an out-of-bounds heap read. The overread bytes are copied into the GetMap reply and sent back to the requesting client, producing a bounded heap information disclosure.
NOTE: https://lists.x.org/archives/xorg-announce/2026-October/003747.html
NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/927ee1282d21550807619521bee909ef62ed0571 (xorg-server-21.1.25)
CheckKeyActions() then validates the wire action count against the stale old width and accepts it. In _XkbSetMap(), SetKeySyms() widens the key (resizing actions to nGroups * newWidth), but SetKeyActions() then resizes again to the old count. A subsequent XkbGetMap request reads XkbKeyNumActions() entries (derived from the new wider key_sym_map.width) from the shorter action allocation, causing an out-of-bounds heap read. The overread bytes are copied into the GetMap reply and sent back to the requesting client, producing a bounded heap information disclosure.
NOTE: https://lists.x.org/archives/xorg-announce/2026-October/003747.html
NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/927ee1282d21550807619521bee909ef62ed0571 (xorg-server-21.1.25)
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | tigervnc | Pending Fix | ||
| Amazon Linux 2023 | tigervnc | Pending Fix | ||
| Amazon Linux 2 - Core | wayland | Not Affected | ||
| Amazon Linux 2023 | wayland | Not Affected | ||
| Amazon Linux 2027 Preview | wayland | Not Affected | ||
| Amazon Linux 2023 | xisxwayland | Not Affected | ||
| Amazon Linux 2027 Preview | xisxwayland | Not Affected | ||
| Amazon Linux 2 - Core | xorg-x11-server | Pending Fix | ||
| Amazon Linux 2023 | xorg-x11-server | Pending Fix | ||
| Amazon Linux 2023 | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xorg-x11-server-Xwayland | Pending Fix | ||
| Amazon Linux 2027 Preview | xwayland-run | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 3.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |