CVE-2026-4367

Name
CVE-2026-4367
Description
A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secalert@redhat.com https://access.redhat.com/security/cve/CVE-2026-4367
secalert@redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2448984
secalert@redhat.com https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/5448e1bd
secalert@redhat.com https://seclists.org/oss-sec/2026/q2/192
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2026/04/21/3
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:30354

Match rules

CPE URI Source package Min version Max version

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libxpm edge-main 3.5.19-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libxpm 3.24-main 3.5.19-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libxpm 3.23-main 3.5.19-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libxpm 3.22-main 3.5.19-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libxpm 3.21-main 3.5.19-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libxpm 3.20-main 3.5.19-r0 Natanael Copa <ncopa@alpinelinux.org> fixed