CVE-2026-59679

EUVD-2026-75300
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked.
A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9 CRITICAL
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 34.57%
Debian logo
Debian Releases
Debian Product
Codename
libxfont
bookworm
unimportant
bookworm (security)
unimportant
forky
1:2.0.9-1
fixed
sid
1:2.0.9-1
fixed
trixie
unimportant
trixie (security)
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxfont
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
libxfont2
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libXfont2-2
suse enterprise desktop 15 SP7
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP4
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP5
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP6
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP7
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP4
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP5
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP6
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP7
2.0.3-150000.3.6.1
fixed
libXfont2-devel
suse enterprise desktop 15 SP7
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP4
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP5
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP6
2.0.3-150000.3.6.1
fixed
suse enterprise sap 15 SP7
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP4
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP5
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP6
2.0.3-150000.3.6.1
fixed
suse enterprise server 15 SP7
2.0.3-150000.3.6.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libXfont2
RHEL 8
0:2.0.3-2.el8_10.3
fixed
RHEL 9
0:2.0.3-12.el9_8.3
fixed
libXfont2-devel
RHEL 8
0:2.0.3-2.el8_10.3
fixed
RHEL 9
0:2.0.3-12.el9_8.3
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libXfont
Amazon Linux 2
0:1.5.4-1.amzn2.0.2
fixed
libXfont-debuginfo
Amazon Linux 2
0:1.5.4-1.amzn2.0.2
fixed
libXfont-devel
Amazon Linux 2
0:1.5.4-1.amzn2.0.2
fixed
libXfont2
Amazon Linux 2
0:2.0.3-1.amzn2.0.2
fixed
Amazon Linux 2023
0:2.0.7-1.amzn2023.0.3
fixed
libXfont2-debuginfo
Amazon Linux 2
0:2.0.3-1.amzn2.0.2
fixed
Amazon Linux 2023
0:2.0.7-1.amzn2023.0.3
fixed
libXfont2-debugsource
Amazon Linux 2023
0:2.0.7-1.amzn2023.0.3
fixed
libXfont2-devel
Amazon Linux 2
0:2.0.3-1.amzn2.0.2
fixed
Amazon Linux 2023
0:2.0.7-1.amzn2023.0.3
fixed