Impact
The libXfont2 font-server client contains an out‑of‑bounds read/write flaw that is triggered when it processes font data received from an external font server. A remote attacker who can run a malicious font server can exploit this by sending crafted font data that causes the client to read or write memory beyond the allocated buffer. If the X server is running with elevated privileges, the corrupted memory can allow the attacker to elevate their own privileges on the host; if the X server runs as an unprivileged user, the overflow may simply crash the server resulting in a denial of service.
Affected Systems
The vulnerability affects the libXfont2 library used by X server implementations on Unix-like systems. No specific vendor product list or version numbers are listed, so all installations that employ the libXfont2 font‑server client and accept external fonts are potentially impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, and while no EPSS value is available, the lack of a KEV listing suggests that widespread exploitation has not yet been observed. The likely attack vector is remote: an attacker must be able to control or supply a malicious font server that the victim’s X server will contact. The flaw requires the victim’s X server to load the defective font; therefore, systems that disable external font loading or run the X server with restricted permissions face a lower exploitation risk.
OpenCVE Enrichment