The Xkbcommon Project maintains a keyboard-mapping and input-processing library that, despite a narrow product scope, sits in the input path of many desktop environments and graphical applications across Linux systems. The durable signal centers on NULL-pointer dereference conditions arising from the library's keyboard-state parsing and symbolic-translation logic, a characteristic pattern in C-based parsing libraries handling complex input formats. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xkbcommon Project over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15857HIGH An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local attackers to crash xkbcommon keymap parsers or possibly have un | Aug 25, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-15861MEDIUM Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser | Aug 25, 2018 | 5.5 | 21 | NO | NO |
CVE-2018-15853MEDIUM Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap | Aug 25, 2018 | 5.5 | 21 | NO | NO |
CVE-2018-15864MEDIUM Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon pars | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15863MEDIUM Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbc | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15862MEDIUM Unchecked NULL pointer usage in LookupModMask in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15859MEDIUM Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer derefe | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15858MEDIUM Unchecked NULL pointer usage when handling invalid aliases in CopyKeyAliasesToKeymap in xkbcomp/keycodes.c in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15856MEDIUM An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbcommon before 0.8.1 could be used by local attackers to cause a denial of service | Aug 25, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-15855MEDIUM Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, | Aug 25, 2018 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xkbcommon Project.
Media articles that mention a CVE ID that affects a product developed by Xkbcommon Project — matched by CVE ID, not by vendor name.