CVE-2026-94287

Summary

A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.

Affected Software

VendorProductVersion RangeStatus
x.orglibXpm0 < 3.5.19affected

Weaknesses

  • CWE-1050: CWE-1050 Excessive platform resource consumption within a loop

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References