Hi, The following vulnerabilities were published for libxi. CVE-2026-93541[0]: | An out-of-bounds read in libXi's XQueryDeviceState() in libXi before | 1.8.4 could be used by a CVE-2026-93542[1]: | An out-of-bounds read in libXi's XI2 class parsing via | size_classes() and copy_classes() in libXi before 1.8.4 could be | used by malicous servers to crash the X client. CVE-2026-93543[2]: | An out-of-bounds read in libXi's XI2 class parser in libXi before | 1.8.4 could be used by malicious X servers to crash an attached X | client. CVE-2026-93544[3]: | An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in | libXi before 1.8.4 can be used by a malicious X server to crash an | attached X client. CVE-2026-93545[4]: | An out-of-bounds read in libXi's XListInputDevices() in libXi before | 1.8.4 could be used by malicious X servers to crash an attached X | client. CVE-2026-94281[5]: | An out-of-bounds read in libXi's XListInputDevices() class parsing | in libXi before 1.8.4 could be used by malicious X servers to crash | an attached X client. and CVE-2026-94282[6]. They are all handled in the not yet merged MR upstream at [7]. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-93541 https://www.cve.org/CVERecord?id=CVE-2026-93541 [1] https://security-tracker.debian.org/tracker/CVE-2026-93542 https://www.cve.org/CVERecord?id=CVE-2026-93542 [2] https://security-tracker.debian.org/tracker/CVE-2026-93543 https://www.cve.org/CVERecord?id=CVE-2026-93543 [3] https://security-tracker.debian.org/tracker/CVE-2026-93544 https://www.cve.org/CVERecord?id=CVE-2026-93544 [4] https://security-tracker.debian.org/tracker/CVE-2026-93545 https://www.cve.org/CVERecord?id=CVE-2026-93545 [5] https://security-tracker.debian.org/tracker/CVE-2026-94281 https://www.cve.org/CVERecord?id=CVE-2026-94281 [6] https://security-tracker.debian.org/tracker/CVE-2026-94282 https://www.cve.org/CVERecord?id=CVE-2026-94282 [7] https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23 Please adjust the affected versions in the BTS as needed. Regards, Salvatore