Opened 5 months ago
Closed 5 months ago
#23175 closed enhancement (fixed)
libXpm-3.5.19 (Xorg library)
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Security release. Fixes CVE-2026-4367.
https://lists.x.org/archives/xorg-announce/2026-April/003691.html
Change History (4)
comment:1 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
comment:3 by , 5 months ago
Offline copy of the security advisory:
====================================================================== X.Org Security Advisory: April 21, 2026 Issue in libXpm prior to version 3.5.19 ====================================================================== An issue has been found in the libXpm library published by X.Org for which we are releasing a security fix for in libXpm-3.5.19. * CVE-2026-4367: libXpm Out-of-bounds read in xpmNextWord() libXpm uses a number of internal helper functions to parse the XPM file format. One of these internal functions, xpmNextString(), checks for the NULL terminator when looking for the end of the current string but not when looking for the beginning of the next string. A small XPM file with a malformed color table definition may cause the function xpmNextWord(), called from xpmParseColors() following a call to xpmNextString(), to start past the actual end of the file, causing an out-of-bound read. Introduced in: Unknown, prior to 3.5.5 (from Xorg 7.1) Fixed in: libXpm-3.5.19 Fix: https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/5448e1bd Found by: Naoki Wakamatsu
Note:
See TracTickets
for help on using tickets.

Fixed at 459ccdf217. Leaving open for SA.