CVE-2026-44950

EUVD-2026-75306
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation.

A malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9 CRITICAL
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 36.93%
Debian logo
Debian Releases
Debian Product
Codename
libxfont
bookworm
unimportant
bookworm (security)
unimportant
forky
1:2.0.9-1
fixed
sid
1:2.0.9-1
fixed
trixie
unimportant
trixie (security)
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxfont
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
libxfont2
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libXfont2-2
suse enterprise desktop 15 SP7
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP4
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP5
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP6
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP7
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP4
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP5
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP6
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP7
2.0.3-150000.3.6.1
fixed
libXfont2-devel
suse enterprise desktop 15 SP7
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP4
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP5
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP6
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP7
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP4
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP5
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP6
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP7
2.0.3-150000.3.6.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libXfont2
RHEL 8
0:2.0.3-2.el8_10.3
fixed
RHEL 9
0:2.0.3-12.el9_8.3
fixed
libXfont2-devel
RHEL 8
0:2.0.3-2.el8_10.3
fixed
RHEL 9
0:2.0.3-12.el9_8.3
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libXfont
Amazon Linux 2
0:1.5.4-1.amzn2.0.2
fixed
libXfont-debuginfo
Amazon Linux 2
0:1.5.4-1.amzn2.0.2
fixed
libXfont-devel
Amazon Linux 2
0:1.5.4-1.amzn2.0.2
fixed
libXfont2
Amazon Linux 2
0:2.0.3-1.amzn2.0.2
fixed
Amazon Linux 2023
0:2.0.7-1.amzn2023.0.3
fixed
libXfont2-debuginfo
Amazon Linux 2
0:2.0.3-1.amzn2.0.2
fixed
Amazon Linux 2023
0:2.0.7-1.amzn2023.0.3
fixed
libXfont2-debugsource
Amazon Linux 2023
0:2.0.7-1.amzn2023.0.3
fixed
libXfont2-devel
Amazon Linux 2
0:2.0.3-1.amzn2.0.2
fixed
Amazon Linux 2023
0:2.0.7-1.amzn2023.0.3
fixed