High severity8.5NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-56001
CVE-2026-56001
Description
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont
Affected products
5- osv-coords4 versionspkg:rpm/almalinux/libXfont2pkg:rpm/almalinux/libXfont2-develpkg:rpm/opensuse/libXfont2&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libXfont2&distro=openSUSE%20Tumbleweed
< 2.0.6-5.el10_2.1+ 3 more
- (no CPE)range: < 2.0.6-5.el10_2.1
- (no CPE)range: < 2.0.6-5.el10_2.1
- (no CPE)range: < 2.0.7-160000.4.1
- (no CPE)range: < 2.0.7-2.1
Patches
Vulnerability mechanics
References
2- gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778nvdPatch
- www.openwall.com/lists/oss-security/2026/07/08/1nvdMailing ListPatchThird Party Advisory
News mentions
0No linked articles in our index yet.