CVE-2018-14598: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 4.2% chance of exploitation in the next 30 days.

An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS (segmentation fault).

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only
  • Fedoraproject Fedora: version 28 only
  • X.org LIBX11: up to and including 1.6.5

Published 2018-08-24. Last modified 2026-06-17.