Xkbcommon is a keyboard-handling library embedded across Linux desktop environments and input-processing pipelines, where its narrow product scope belies significant downstream reach. Vulnerabilities in this library recur through memory-management and resource-control weakness classes including NULL-pointer dereferences, infinite loops, uncontrolled resource consumption, and use-after-free conditions, reflecting the complexity of state management in keyboard-layout and input-event parsing. Defenders should track patches to this library as part of broader desktop and input-stack updates; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xkbcommon over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15857HIGH An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local attackers to crash xkbcommon keymap parsers or possibly have un | Aug 25, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-15861MEDIUM Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser | Aug 25, 2018 | 5.5 | 21 | NO | NO |
CVE-2018-15853MEDIUM Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap | Aug 25, 2018 | 5.5 | 21 | NO | NO |
CVE-2018-15864MEDIUM Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon pars | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15863MEDIUM Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbc | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15862MEDIUM Unchecked NULL pointer usage in LookupModMask in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15859MEDIUM Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer derefe | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15858MEDIUM Unchecked NULL pointer usage when handling invalid aliases in CopyKeyAliasesToKeymap in xkbcomp/keycodes.c in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15856MEDIUM An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbcommon before 0.8.1 could be used by local attackers to cause a denial of service | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15855MEDIUM Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, | Aug 25, 2018 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xkbcommon.
Media articles that mention a CVE ID that affects a product developed by Xkbcommon — matched by CVE ID, not by vendor name.