---
id: CVE-2026-4367
title: A flaw was found in libXpm
summary: >-
  A flaw was found in libXpm. A local user with low privileges could exploit an
  Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing
  a specially crafted or very small XPM (X PixMap) image file. This improper
  valid…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-125
published: '2026-06-16'
updated: '2026-07-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4367'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:30354'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:47072'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-4367'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2448984'
    label: secalert@redhat.com
  - url: 'https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/5448e1bd'
    label: secalert@redhat.com
  - url: 'https://seclists.org/oss-sec/2026/q2/192'
    label: secalert@redhat.com
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/21/3'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00129
epssPercentile: 0.02876
ingestedAt: '2026-07-28T21:39:18.169Z'
---

## Overview

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
