CVE-2026-56002
published 2026-07-08CVE-2026-56002: A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code…
PriorityP358high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.56%
44.6th percentile
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ubuntu | libxfont | — | — |
| x.org | libxfont2 | < 2.0.8 | 2.0.8 |
| x.org | libxfont2 | — | — |
| x | libxfont | < 2.0.8 | 2.0.8 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libXfont vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 8.8
CVE-2026-56003 [HIGH] libXfont vulnerabilities
Title: libXfont vulnerabilities
Summary: Several security issues were fixed in libXfont.
It was discovered that libXfont incorrectly handled scaling bitmap
fonts, leading to a heap buffer overflow. An attacker able to access
the X server could use this issue to cause libXfont to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2026-56001)
It was discovered that libXfont did not properly check glyph bounds
when reading PCF fonts, leading to a heap buffer overflow. An
authenticated X client could use this issue to cause libXfont to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2026-56002)
It was discovered that libXfont did not properly check the size of the
property buffer when parsing PCF fonts, leading to a heap buff
Red Hat
libXfont2: PCF Font Parsing Heap Buffer Overflow
vendor_redhat·2026-07-08·CVSS 8.5
CVE-2026-56002 [HIGH] CWE-787 libXfont2: PCF Font Parsing Heap Buffer Overflow
libXfont2: PCF Font Parsing Heap Buffer Overflow
A flaw was found in libXfont2. A specially crafted PCF (Portable Compiled Format) font file, when processed by libXfont2, can lead to a buffer overflow. This occurs because the font parsing process does not properly validate the size of a bitmap buffer against the glyph metrics provided in the malicious font file. An attacker could exploit this vulnerability by providing a malicious font, potentially leading to arbitrary code execution or a denial of service.
Statement: This is an Important flaw in libXfont2, affecting Red Hat Enterprise Linux. A heap buffer overflow during PCF font file parsing can lead to arbitrary code execution or denial of service. Exploitation requires processing a specially crafted font file, but does not necessitat
GHSA
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server.
ghsa_unreviewed·2026-07-08
CVE-2026-56002 [HIGH] CWE-122 A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server.
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server.
No detection rules found.
No public exploits indexed.
2026-07-08
Published