cbcvebase.

Suse Linux Enterprise Server 15 Sp7 vulnerabilities

3 known vulnerabilities affecting suse/suse_linux_enterprise_server_15_sp7.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1

Vulnerabilities

Page 1 of 1
CVE-2026-44950P3CRITICALCVSS 9.0≥ ?, < 2.0.3-150000.3.6.12026-09-10
CVE-2026-44950 [CRITICAL] CWE-122 CVE-2026-44950: fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap in fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation. A malicious font server can send
nvd
CVE-2026-59679P3CRITICALCVSS 9.0≥ ?, < 2.0.3-150000.3.6.12026-09-10
CVE-2026-59679 [CRITICAL] CWE-787 CVE-2026-59679: fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character enc fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised fo
nvd
CVE-2026-41054P3HIGHCVSS 7.8≥ ?, < 1.9.14-150600.11.6.12026-05-20
CVE-2026-41054 [HIGH] CWE-305 CVE-2026-41054: In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execution**. The code proceeds to the `switch` statement, allowi
nvd
Suse Linux Enterprise Server 15 Sp7 vulnerabilities | cvebase