CVE-2026-34003

Publish date: April 15, 2026
Severity
High
CVSS score
7.8
Package
xorg-server
Affected versions
>= 2:21.1.16-1.3+deb13u1+e1

A flaw exists in the X.Org X server's validation of XKB key types requests. A local attacker can send a specially crafted request to the X server, which may lead to an out-of-bounds memory access vulnerability. This vulnerability could result in the disclosure of sensitive information or cause the server to crash, resulting in a Denial of Service (DoS). In specific configurations, more severe outcomes could potentially occur.