Description
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.
Published: 2026-07-08
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap buffer overflow in the pcfReadFont() function of libXfont2 occurs when the library parses PCF font files that lack proper glyph bounds checking, a weakness classified as CWE-122 and CWE-787. If an attacker supplies a crafted font file, the overflow can overwrite heap memory and execute arbitrary code with the privileges of the X server process, potentially granting full system compromise.

Affected Systems

The flaw affects any installation of X.Org libXfont2 before version 2.0.8. It applies to all systems running an X11 display server, such as typical Linux or Unix desktop environments and remote X forwarding sessions, where an authenticated X client can provide its own font file to the server.

Risk and Exploitability

Scored with a CVSS of 8.5, the vulnerability poses high severity. The EPSS indicates an exploitation probability below 1%, and the issue is not listed in the CISA KEV catalog, suggesting no widely available exploits at this time. The attack vector requires an authenticated X client, which can be any user logged into a graphical session or a client connected via remote X forwarding. Successful exploitation grants code execution in the X server’s context.

Generated by OpenCVE AI on July 29, 2026 at 14:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade libXfont2 to version 2.0.8 or later and restart the X server.
  • Apply the patch from the commit b4389e0b1d84a690b819bb27b1439968811a3674, if upgrading may not be immediately possible.
  • Restrict X client authentication to limit the ability of authenticated users to provide arbitrary font files to the server.

Generated by OpenCVE AI on July 29, 2026 at 14:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4678-1 libxfont security update
Debian DSA Debian DSA DSA-6388-1 libxfont security update
Ubuntu USN Ubuntu USN USN-8560-1 libXfont vulnerabilities
History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared X.org libxfont
Vendors & Products X.org libxfont

Thu, 09 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Important


Wed, 08 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.
Title libXfont2 PCF Font Parsing Heap Buffer Overflow
First Time appeared X.org
X.org libxfont2
Weaknesses CWE-122
CPEs cpe:2.3:a:x.org:libxfont2:*:*:*:*:*:*:*:*
Vendors & Products X.org
X.org libxfont2
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

X.org Libxfont Libxfont2
cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-07-09T03:55:46.745Z

Reserved: 2026-06-18T09:26:55.988Z

Link: CVE-2026-56002

cve-icon Vulnrichment

Updated: 2026-07-08T12:07:30.351Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-08T00:00:00Z

Links: CVE-2026-56002 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses