Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2656 articles · 130317 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-34003PATCHED
Red Hat · Red Hat Enterprise Linux 10

Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access

Description

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 10—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
red hatred hat enterprise linuxmitre_affected90%

References

  • https://access.redhat.com/errata/RHSA-2026:10739(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:11352(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:11369(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-34003(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2451113(issue-tracking, x_refsource_REDHAT)

Related News (2 articles)

Tier A
Microsoft MSRC5h ago
CVE-2026-34003 Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-34003 | X.org X Server XKB Key Types Request out-of-bounds
→ No new info (linked only)
CVSS 3.17.8 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
0:1.15.0-6.el9_7.1
CWECWE-125
PublishedApr 23, 2026
Last enriched5d ago
Trending Score36
Source articles2
Independent2
Info Completeness6/14
Missing: versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-34001
Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption
Trending: 36
NONECVE-2026-33999
Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling
Trending: 36
NONECVE-2026-7309
Openshift-controller-manager: openshift container platform: information disclosure via environment variable injection
Trending: 31
HIGHPRE-CVE
Multiple Vulnerabilities in Red Hat Products Allow Remote Code Execution, File Manipulation, and Denial of Service
Trending: 24
MEDIUMPRE-CVE
Multiple Denial of Service Vulnerabilities in Red Hat Virtualization
Trending: 23

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 23, 2026
Discovered by ZDM
Apr 23, 2026
Patch Available
Apr 28, 2026