CVE-2026-94287: X.org Libxpm
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.
Affected products
- X.org Libxpm: before 3.5.19 (fixed in 3.5.19)
Published 2026-09-28. Last modified 2026-09-29.