CVE-2026-94287

Published: Set 28, 2026 Last Modified: Set 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,5
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.

1050

Excessive Platform Resource Consumption within a Loop

Incomplete
Common Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Resource Consumption (Other) Reduce Performance
Applicable Platforms
All platforms may be affected
View CWE Details
https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/32/diffs?commit…