VDB
DEBIAN-CVE-2018-15863
DEBIAN-CVE-2018-15863
PUBLISHED
CVSS 5.5 MEDIUM
Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file with a no-op modmask expression.
Risk Scores
CVSS 3.0
5.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | x11-xkb-utils | 0, 7.7+9, 0 |
| Debian:12 | libxkbcommon | 0, 0, 0 |
| Debian:13 | x11-xkb-utils | 0, 7.7+9, 0 |
| Debian:13 | libxkbcommon | 0, 0, 0 |
| Debian:14 | libxkbcommon | 0, 0, 0 |
| Debian:11 | x11-xkb-utils | 7.7+8, 7.7+6, 7.7+7 |
| Debian:12 | x11-xkb-utils | 7.7+9, 7.7+8, 7.7+7 |
| Debian:11 | libxkbcommon | 0, 0, 0 |
Exploit Intelligence
- errata77.html (github-poc)
Timeline
- Aug 25, 2018 CVE Published
- Apr 28, 2026 CVE Updated