{"id":"CVE-2026-88806","title":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.","summary":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"x.org","product":"libX11","affected":["libX11 < 1.8.14"],"published":"2026-09-21","updated":"2026-09-22","sourceUpdated":"2026-09-22T19:40:05.870","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88806","references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309","label":"meissner@suse.de"}],"tags":["nvd","cve.org"],"epss":0.00336,"epssPercentile":0.24315,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-21T00:00:00+00:00"},"ingestedAt":"2026-09-21T14:38:56.363Z","slug":"CVE-2026-88806","body":"## Overview\n\nA malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}