High severity8.5NVD Advisory· Published Jul 8, 2026· Updated Jul 13, 2026
CVE-2026-56002
CVE-2026-56002
Description
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server.
Affected products
5- osv-coords4 versionspkg:rpm/almalinux/libXfont2pkg:rpm/almalinux/libXfont2-develpkg:rpm/opensuse/libXfont2&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libXfont2&distro=openSUSE%20Tumbleweed
< 2.0.6-5.el10_2.1+ 3 more
- (no CPE)range: < 2.0.6-5.el10_2.1
- (no CPE)range: < 2.0.6-5.el10_2.1
- (no CPE)range: < 2.0.7-160000.4.1
- (no CPE)range: < 2.0.7-2.1
Patches
Vulnerability mechanics
References
2- gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bb27b1439968811a3674nvdPatch
- www.openwall.com/lists/oss-security/2026/07/08/1nvdMailing ListPatchThird Party Advisory
News mentions
0No linked articles in our index yet.