Impact
The vulnerability is an integer overflow in the BitmapScaleBitmaps function of libXfont2 that causes a heap buffer overflow. When an attacker can send data to the X server, execution can occur under the server’s privileges. This flaw, classified as CWE‑122, carries a CVSS score of 8.5, indicating a serious impact on confidentiality, integrity, and availability.
Affected Systems
All versions of the X.Org libXfont2 library older than 2.0.8 are affected. The flaw exists in any installation that contains a pre‑2.0.8 build of libXfont2, as long as the X server is running.
Risk and Exploitability
Based on the description, the attack vector requires the ability to communicate with the X server, which can be achieved locally or by remote clients when the server accepts network connections. The CVSS score of 8.5 reflects a high risk of successful exploitation under typical conditions, yet the EPSS score of < 1% indicates that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalogue, so no widespread active exploitation has been reported. Nonetheless, the high severity and the fact that the flaw can be triggered by any client that has access to the server make it a critical threat for systems exposed to remote or untrusted clients.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN