X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7946