Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4367

26
FAUCET Score

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

First published: Jun 16, 2026Last modified: Jul 28, 2026

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat Enterprise Linux 10
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 6
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 7
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 8
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9
All Versions ImpactedCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
2.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 20th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

microsoftpatch availablevia msrc
Product: azl3 libXpm 3.5.17-1 on Azure Linux 3.0Fixed in: 3.5.19-1
microsoftpatch availablevia msrc
Product: 21463-17084Fixed in: 3.5.19-1
ubuntupatch availablevia ubuntu_usn
Product: libxpm (jammy)Fixed in: 1:3.5.12-1ubuntu0.22.04.3
ubuntupatch availablevia ubuntu_usn
Product: libxpm (noble)Fixed in: 1:3.5.17-1ubuntu0.24.04.1
ubuntupatch availablevia ubuntu_usn
Product: libxpm (resolute)Fixed in: 1:3.5.17-1ubuntu0.26.04.1

Vendor Advisories (2)

ubuntuUSN-8600-1

libXpm vulnerability

Jul 23, 2026
microsoft2026-Jun/CVE-2026-4367Moderate

Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing

Jun 9, 2026

References

openwall.com / lists/oss-security/2026/04/21/3
access.redhat.com / errata/RHSA-2026:30354
access.redhat.com / errata/RHSA-2026:47072
access.redhat.com / security/cve/CVE-2026-4367
bugzilla.redhat.com / show_bug.cgi
gitlab.freedesktop.org / xorg/lib/libxpm/-/commit/5448e1bd
seclists.org / oss-sec/2026/q2/192