CVE-2026-55999
published 2026-07-08CVE-2026-55999: Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.6th percentile
Local attackers with a X connection able to provide PCX fonts to the X
server xorg-server before 21.2.24 and xwayland before 24.1.13 could
cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| the_x.org_foundation | xorg-x11-server | — | — |
| x.org | x_server | < 21.2.24 | 21.2.24 |
| x.org | xorg-server | < 21.1.24 | 21.1.24 |
| x.org | xwayland | < 24.1.13 | 24.1.13 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing gly
ghsa_unreviewed·2026-07-08
CVE-2026-55999 [HIGH] CWE-122 Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing gly
Local attackers with a X connection able to provide PCX fonts to the X
server xorg-server before 21.2.24 and xwayland before 24.1.13 could
cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
Red Hat
xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow
vendor_redhat·2026-07-08·CVSS 8.5
CVE-2026-55999 [HIGH] CWE-805 xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow
xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow
A flaw was found in the glamor_font_get() function of the xorg-x11-server. This vulnerability, a heap buffer overflow, occurs when the server processes a specially crafted PCF font file where individual glyph metrics exceed the declared maximum bounds. An authenticated X client can exploit this by loading a malicious font and drawing text, potentially leading to arbitrary code execution with attacker-controlled content and extent. This affects servers utilizing the glamor acceleration backend, such as Xorg with the modesetting driver and Xwayland.
Statement: This Important flaw in xorg-x11-server allows an authenticated X client to achieve arbitrary code execution. By processing a malicious PCF font file where glyph metric
No detection rules found.
No public exploits indexed.
2026-07-08
Published