CVE-2026-93524

Public on 2026-10-09
Modified on 2026-10-09
Description
CheckKeySyms() in xkb/xkb.c populates a symsPerKey[] validation array with new key widths for keys in the SetMap request range, then continues filling entries for keys beyond the range. However, the second loop starts at index i = nKeySyms (the first loop's counter) rather than i = firstKeySym + nKeySyms. When firstKeySym is large and nKeySyms is small, the second loop overwrites symsPerKey[target] with the old width from the existing map.

CheckKeyActions() then validates the wire action count against the stale old width and accepts it. In _XkbSetMap(), SetKeySyms() widens the key (resizing actions to nGroups * newWidth), but SetKeyActions() then resizes again to the old count. A subsequent XkbGetMap request reads XkbKeyNumActions() entries (derived from the new wider key_sym_map.width) from the shorter action allocation, causing an out-of-bounds heap read. The overread bytes are copied into the GetMap reply and sent back to the requesting client, producing a bounded heap information disclosure.

NOTE: https://lists.x.org/archives/xorg-announce/2026-October/003747.html
NOTE: Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/927ee1282d21550807619521bee909ef62ed0571 (xorg-server-21.1.25)
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
3.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core tigervnc Pending Fix
Amazon Linux 2023 tigervnc Pending Fix
Amazon Linux 2 - Core wayland Not Affected
Amazon Linux 2023 wayland Not Affected
Amazon Linux 2027 Preview wayland Not Affected
Amazon Linux 2023 xisxwayland Not Affected
Amazon Linux 2027 Preview xisxwayland Not Affected
Amazon Linux 2 - Core xorg-x11-server Pending Fix
Amazon Linux 2023 xorg-x11-server Pending Fix
Amazon Linux 2023 xorg-x11-server-Xwayland Pending Fix
Amazon Linux 2027 Preview xorg-x11-server-Xwayland Pending Fix
Amazon Linux 2027 Preview xwayland-run Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N