High severity8.5NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-56003
CVE-2026-56003
Description
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.
Affected products
5- osv-coords4 versionspkg:rpm/almalinux/libXfont2pkg:rpm/almalinux/libXfont2-develpkg:rpm/opensuse/libXfont2&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libXfont2&distro=openSUSE%20Tumbleweed
< 2.0.3-2.el8_10.1+ 3 more
- (no CPE)range: < 2.0.3-2.el8_10.1
- (no CPE)range: < 2.0.3-2.el8_10.1
- (no CPE)range: < 2.0.7-160000.4.1
- (no CPE)range: < 2.0.7-2.1
Patches
Vulnerability mechanics
References
2- gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/dff957a5158da038a282a59a31fe736702732939nvdPatch
- www.openwall.com/lists/oss-security/2026/07/08/1nvdMailing ListPatchThird Party Advisory
News mentions
0No linked articles in our index yet.