PT-2026-56334 · X.Org Foundation+1 · Xorg-Server+2

CVE-2026-55999

·

Published

2026-07-08

·

Updated

2026-08-26

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xorg-server versions prior to 21.2.24 xwayland versions prior to 24.1.13
Description Local attackers with an X connection can cause a heap buffer overflow by providing PCX fonts to the X server. This occurs due to missing glyph boundary checks within the SetFont() function. A heap buffer overflow is a memory corruption issue where a program writes more data to a heap-allocated buffer than it can hold, potentially leading to crashes or arbitrary code execution.
Recommendations Update xorg-server to version 21.2.24 or later. Update xwayland to version 24.1.13 or later.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:38486
ALSA-2026:38487
ALSA-2026:38488
ALSA-2026:38489
ALSA-2026:38490
AZL-92196
CVE-2026-55999
ECHO-D009-B514-1211
OESA-2026-3026
OPENSUSE-SU-2026:11227-1
OPENSUSE-SU-2026:11244-1
OPENSUSE-SU-2026:21273-1
OPENSUSE-SU-2026:21283-1
RHSA-2026:38486
RHSA-2026:38487
RHSA-2026:38488
RHSA-2026:38489
RHSA-2026:38490
RHSA-2026:49515
RHSA-2026:49516
RHSA-2026:49605
RHSA-2026:49606
RHSA-2026:49608
RHSA-2026:50100
RHSA-2026:50116
RHSA-2026:50117
RHSA-2026:50718
RHSA-2026:52392
RHSA-2026:52397
RHSA-2026:52398
RHSA-2026:53450
SUSE-SU-2026:22617-1
SUSE-SU-2026:2786-1
SUSE-SU-2026:2787-1
SUSE-SU-2026:2788-1
SUSE-SU-2026:2789-1
SUSE-SU-2026:2791-1
SUSE-SU-2026:2792-1
ZDI-26-409

Affected Products

Rocky Linux
Xorg-Server
Xwayland