#1148733 libx11: CVE-2026-88806

Package:
src:libx11
Source:
src:libx11
Submitter:
Salvatore Bonaccorso
Date:
2026-09-22 18:52:02 UTC
Severity:
normal
Tags:
#1148733#5
Date:
2026-09-22 18:51:23 UTC
From:
To:
Hi,

The following vulnerability was published for libx11.

CVE-2026-88806[0]:
| A malicious X server could exploit a buffer overflow in libX11
| before 1.8.14 during handling of XkbGetMap overflowing the
| key_sym_map.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-88806
https://www.cve.org/CVERecord?id=CVE-2026-88806
[1] https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore