CVE-2026-88807
libXrender RenderQueryPictFormats Reply Heap-based Buffer Overflow
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.
| CWE | CWE-122 |
| Vendor | x.org |
| Product | libxrender |
| Published | Sep 21, 2026 |
| Last Updated | Sep 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for x.org libxrender
Be the first to know when new unknown vulnerabilities affecting x.org libxrender are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
X.org / libXrender
0 < 0.9.13
References
Credits
Adam Bedard working with TrendAI Zero Day Initiative Claude:claude-opus-4-6