CVE-2026-4367

Source
https://cve.org/CVERecord?id=CVE-2026-4367
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4367.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-4367
Downstream
Related
Published
2026-06-16T16:50:15.037Z
Modified
2026-07-30T03:52:38.881714314Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing
Details

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the xpmNextWord() function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

Database specific
{
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4367.json",
    "cna_assigner": "redhat"
}
References

Affected packages

Git / gitlab.freedesktop.org/xorg/lib/libxpm

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/xorg/lib/libxpm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4367.json"