Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-88807: libxrender may let attackers run code on your server
CVE-2026-88807 · published 4 days ago
Summary
The libxrender library used on Debian 12 systems can be tricked into running malicious programs. This could let an attacker take control of the affected machine. Install the latest libxrender updates from your distribution as soon as possible.
What to do
- Update libxrender to version 1:0.9.10-1.1.aikido.1.
- Update rootio-libxrender to version 1:0.9.10-1.1.aikido.1.
- Update x.org libxrender to version 0.9.13 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | libxrender | All versions |
| Ubuntu:14.04:LTS | canonical | libxrender | All versions |
| – | x.org | libxrender | < 0.9.13 |
| Root:Debian:12 | – | libxrender |
< 1:0.9.10-1.1.aikido.1 Fix: upgrade to 1:0.9.10-1.1.aikido.1
|
| Root:Debian:12 | – | rootio-libxrender |
< 1:0.9.10-1.1.aikido.1 Fix: upgrade to 1:0.9.10-1.1.aikido.1
|
Original advisory text
CVE-2026-88807 in libxrender - Patched by Root
Root has patched CVE-2026-88807 in the libxrender package for Root:Debian:12. Multiple fixed versions available.
References
- https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-88807 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-88807 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-88807 Third Party Advisory
Severity
9.4
Critical
CVSS 4.0: 8.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published25 Sep 2026
Updated27 Sep 2026
First seen21 Sep 2026
Sources
CVE-2026-88807 · NVD
CVE-2026-88807 · MITRE
DEBIAN-CVE-2026-88807 · OSV
UBUNTU-CVE-2026-88807 · OSV
Track software like this
Free during beta