CVE-2026-34000: Out-of-bounds Read in Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support
CVE-2026-34000 is an out-of-bounds read vulnerability in the X.Org X server's XKB geometry processing components affecting Red Hat Enterprise Linux versions 9.2 through 9.8. This flaw can allow an attacker with local or remote access to the X11 server to disclose memory contents or cause a denial of service by crashing the server. Red Hat has released security advisories and updates addressing this issue as part of important security updates for xorg-x11-server-Xwayland and related packages.
AI Analysis
Technical Summary
CVE-2026-34000 is an out-of-bounds read vulnerability in the X.Org X server, specifically in the XKB geometry processing functions CheckSetGeom() and XkbAddGeomKeyAlias. This vulnerability affects Red Hat Enterprise Linux versions from 9.2 up to and including 9.8. Exploitation can lead to information disclosure or denial of service by crashing the X11 server. Red Hat has issued security advisories (RHSA-2026:19342 and RHSA-2026:20547) that include patches for xorg-x11-server-Xwayland and related packages to remediate this vulnerability.
Potential Impact
The vulnerability allows an attacker with local or remote access to the X11 server to potentially read out-of-bounds memory, leading to information disclosure. It can also cause a denial of service by crashing the X.Org X server. The CVSS v3.1 base score is 6.1 (medium severity), reflecting the potential for high confidentiality impact and low availability impact. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability in xorg-x11-server-Xwayland and related packages. Users should apply the updates provided in Red Hat advisories RHSA-2026:19342 and RHSA-2026:20547 as soon as possible. Detailed update instructions are available at https://access.redhat.com/articles/11258. Since this is an important security update, applying the official patches is the recommended mitigation.
CVE-2026-34000: Out-of-bounds Read in Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support
Description
CVE-2026-34000 is an out-of-bounds read vulnerability in the X.Org X server's XKB geometry processing components affecting Red Hat Enterprise Linux versions 9.2 through 9.8. This flaw can allow an attacker with local or remote access to the X11 server to disclose memory contents or cause a denial of service by crashing the server. Red Hat has released security advisories and updates addressing this issue as part of important security updates for xorg-x11-server-Xwayland and related packages.
CVSS v3.1
Score 6.1medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-34000 is an out-of-bounds read vulnerability in the X.Org X server, specifically in the XKB geometry processing functions CheckSetGeom() and XkbAddGeomKeyAlias. This vulnerability affects Red Hat Enterprise Linux versions from 9.2 up to and including 9.8. Exploitation can lead to information disclosure or denial of service by crashing the X11 server. Red Hat has issued security advisories (RHSA-2026:19342 and RHSA-2026:20547) that include patches for xorg-x11-server-Xwayland and related packages to remediate this vulnerability.
Potential Impact
The vulnerability allows an attacker with local or remote access to the X11 server to potentially read out-of-bounds memory, leading to information disclosure. It can also cause a denial of service by crashing the X.Org X server. The CVSS v3.1 base score is 6.1 (medium severity), reflecting the potential for high confidentiality impact and low availability impact. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability in xorg-x11-server-Xwayland and related packages. Users should apply the updates provided in Red Hat advisories RHSA-2026:19342 and RHSA-2026:20547 as soon as possible. Detailed update instructions are available at https://access.redhat.com/articles/11258. Since this is an important security update, applying the official patches is the recommended mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-03-25T04:53:13.614Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-34000","vendor":"Red Hat"}]
Threat ID: 69fa191dcbff5d86100ff6c8
Added to database: 05/05/2026, 16:21:49 UTC
Last enriched: 07/06/2026, 00:43:15 UTC
Last updated: 08/01/2026, 19:21:23 UTC
Views: 103
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.