EIP-2026-103036

PRE-CVE

X 11.0/3.3.3/3.3.4/3.3.5/3.3.6/4.0 - libX11 '_XAsyncReply()' Stack Corruption

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103036. PoCs published by Chris Evans.

AI-analyzed exploit summary This exploit targets a stack corruption vulnerability in the _XAsyncReply() function of libX11 by sending a malicious X server response with a negative size value. It overwrites the return address on the stack, potentially leading to arbitrary code execution.

Description

X 11.0/3.3.3/3.3.4/3.3.5/3.3.6/4.0 - libX11 '_XAsyncReply()' Stack Corruption

Exploits (1)

exploitdb WORKING POC VERIFIED
by Chris Evans · clocallinux
https://www.exploit-db.com/exploits/20045

This exploit targets a stack corruption vulnerability in the _XAsyncReply() function of libX11 by sending a malicious X server response with a negative size value. It overwrites the return address on the stack, potentially leading to arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: libX11 (XFree86 and potentially X11R6.x)
No auth needed
Prerequisites: Local access to run a fake X server on port 6000 · X server not already running on port 6000 · Presence of setuid X applications like xterm
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026