CVE-2026-56003
published 2026-07-08CVE-2026-56003: A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.62%
47.5th percentile
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ubuntu | libxfont | — | — |
| x.org | libxfont2 | < 2.0.8 | 2.0.8 |
| x.org | libxfont2 | — | — |
| x | libxfont | >= 2.0.0 < 2.0.8 | 2.0.8 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libXfont vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 8.8
CVE-2026-56003 [HIGH] libXfont vulnerabilities
Title: libXfont vulnerabilities
Summary: Several security issues were fixed in libXfont.
It was discovered that libXfont incorrectly handled scaling bitmap
fonts, leading to a heap buffer overflow. An attacker able to access
the X server could use this issue to cause libXfont to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2026-56001)
It was discovered that libXfont did not properly check glyph bounds
when reading PCF fonts, leading to a heap buffer overflow. An
authenticated X client could use this issue to cause libXfont to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2026-56002)
It was discovered that libXfont did not properly check the size of the
property buffer when parsing PCF fonts, leading to a heap buff
Red Hat
libXfont2: computeProps Property Buffer Heap Buffer Overflow
vendor_redhat·2026-07-08·CVSS 8.8
CVE-2026-56003 [HIGH] libXfont2: computeProps Property Buffer Heap Buffer Overflow
libXfont2: computeProps Property Buffer Heap Buffer Overflow
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.
Package: libXfont2 (Red Hat Enterprise Linux 10) - Affected
Package: libXfont2 (Red Hat Enterprise Linux 7) - Affected
Package: libXfont2 (Red Hat Enterprise Linux 9) - Affected
GHSA
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using
ghsa_unreviewed·2026-07-08
CVE-2026-56003 [HIGH] CWE-122 A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.
No detection rules found.
No public exploits indexed.
2026-07-08
Published