<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:46:53 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:6497 — Moderate: libX11 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:6497</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libX11, AlmaLinux:9: libX11-common, AlmaLinux:9: libX11-devel, AlmaLinux:9: libX11-xcb&lt;/p&gt;
&lt;p&gt;The libX11 packages contain the core X11 protocol client library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libX11: InitExt.c can overwrite unintended portions of the Display structure if the extension request leads to a buffer overflow (CVE-2023-3138)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libX11, AlmaLinux:9: libX11-common, AlmaLinux:9: libX11-devel, AlmaLinux:9: libX11-xcb&lt;/p&gt;
&lt;p&gt;The libX11 packages contain the core X11 protocol client library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libX11: InitExt.c can overwrite unintended portions of the Display structure if the extension request leads to a buffer overflow (CVE-2023-3138)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:6497</guid>
    </item>
    <item>
      <title>bdu:2023-03596</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03596</link>
      <description>bdu:2023-03596</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03596</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-3138 — CVE-2023-3138 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-3138</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-3138</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0385 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385</link>
      <description>certfr-2024-avi-0385</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385</guid>
    </item>
    <item>
      <title>EUVD-2026-7065</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-7065</link>
      <description>EUVD-2026-7065</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-7065</guid>
    </item>
    <item>
      <title>fkie_cve-2023-3138</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3138</link>
      <description>&lt;p&gt;A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-3138</guid>
    </item>
    <item>
      <title>GHSA-849h-8wj5-xmx8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-849h-8wj5-xmx8</link>
      <description>&lt;p&gt;A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-849h-8wj5-xmx8</guid>
    </item>
    <item>
      <title>gsd-2023-3138</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-3138</link>
      <description>gsd-2023-3138</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-3138</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-3138 — A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not c…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-3138</link>
      <description>msrc_CVE-2023-3138</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-3138</guid>
    </item>
    <item>
      <title>OESA-2023-1376 — libX11 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1376</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libX11&lt;/p&gt;
&lt;p&gt;Core X11 protocol client library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.(CVE-2023-3138)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libX11&lt;/p&gt;
&lt;p&gt;Core X11 protocol client library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.(CVE-2023-3138)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1376</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13008-1 — libX11-6-1.8.5-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13008-1</link>
      <description>&lt;p&gt;libX11-6-1.8.5-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libX11-6-1.8.5-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13008-1</guid>
    </item>
    <item>
      <title>RHSA-2024:1088 — Red Hat Security Advisory: libX11 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:1088</link>
      <description>&lt;p&gt;libX11: InitExt.c can overwrite unintended portions of the Display structure if the extension request leads to a buffer overflow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libX11: InitExt.c can overwrite unintended portions of the Display structure if the extension request leads to a buffer overflow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:1088</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:2531-1 — Security update for libX11</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:2531-1</link>
      <description>&lt;p&gt;Security update for libX11&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libX11&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:2531-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-3138</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3138</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libx11, Ubuntu:Pro:16.04:LTS: libx11, Ubuntu:Pro:18.04:LTS: libx11, Ubuntu:20.04:LTS: libx11, Ubuntu:22.04:LTS: libx11&lt;/p&gt;
&lt;p&gt;A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libx11, Ubuntu:Pro:16.04:LTS: libx11, Ubuntu:Pro:18.04:LTS: libx11, Ubuntu:20.04:LTS: libx11, Ubuntu:22.04:LTS: libx11&lt;/p&gt;
&lt;p&gt;A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3138</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1485 — X.Org X11: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1485</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in X.Org X11 ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in X.Org X11 ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1485</guid>
    </item>
  </channel>
</rss>
