CVE-2026-94287
Publication date 28 September 2026
Last updated 1 October 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libxpm | 26.04 LTS resolute |
Fixed 1:3.5.17-1ubuntu0.26.04.2
|
| 24.04 LTS noble |
Fixed 1:3.5.17-1ubuntu0.24.04.2
|
|
| 22.04 LTS jammy |
Fixed 1:3.5.12-1ubuntu0.22.04.4
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
|
| motif | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
Notes
alexmurray
motif contains a vendored copy of libxpm under lib/Xm/ with files prefixed by Xpm eg. the file src/parse.c in libxpm is lib/Xm/Xpmparse.c
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.5 · Medium
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References
Related Ubuntu Security Notices (USN)
- USN-8862-1
- libXpm vulnerability
- 1 October 2026