There are 4 open security issues in trixie.
4 issues left for the package maintainer to handle:
- CVE-2026-88806:
(needs triaging)
A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.
- CVE-2026-94283:
(needs triaging)
An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
- CVE-2026-94284:
(needs triaging)
An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
- CVE-2026-94285:
(needs triaging)
An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
You can find information about how to handle these issues in the security team's documentation.