PT-2026-56390 · Libxfont2+2 · Libxfont2+2

CVE-2026-56002

·

Published

2026-07-08

·

Updated

2026-07-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libXfont2 versions prior to 2.0.8
Description A heap bufferflow occurs in the pcfReadFont() function due to missing glyph bounds checking. This allows an authenticated X client to execute arbitrary code within the X server.
Recommendations Update libXfont2 to version 2.0.8 or later.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47079
ALSA-2026:47084
ALSA-2026:47103
AZL-92087
CVE-2026-56002
ECHO-4E4F-E6D6-0780
OESA-2026-3055
OPENSUSE-SU-2026:11233-1
OPENSUSE-SU-2026:21284-1
RHSA-2026:51058
RHSA-2026:51059
RHSA-2026:51060
RHSA-2026:51061
RHSA-2026:51062
RHSA-2026:51063
RHSA-2026:51066
RHSA-2026:51067
SUSE-SU-2026:22614-1
SUSE-SU-2026:2793-1
SUSE-SU-2026:2794-1
USN-8560-1
ZDI-26-407

Affected Products

Rocky Linux
Ubuntu
Libxfont2