CVE-2026-88807: X.org Libxrender

High severity, CVSS 8.9. EPSS: 0.3% chance of exploitation in the next 30 days.

A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.

Affected products

  • X.org Libxrender: before 0.9.13 (fixed in 0.9.13)

Published 2026-09-21. Last modified 2026-09-22.