Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44950

Источник: debian

Описание

[Font Server Client Cumulative Glyph Data Heap Buffer Overflow]

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxfontfixed1:2.0.9-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2026/08/05/1

  • Fixed by: https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/c2d222bb22c623d8a40f3275077fc7e6617f2c8a (libXfont2-2.0.9)

  • Disabled support to connect to font server since 1:1.4.7-1

Связанные уязвимости

ubuntu
4 дня назад

[Font Server Client Cumulative Glyph Data Heap Buffer Overflow]

CVSS3: 7.5
redhat
3 дня назад

A flaw was found in the libXfont2 font-server client. This heap buffer overflow vulnerability allows a malicious font server to send specially crafted glyph data. The fs_read_glyphs() function fails to properly validate the total size of the incoming data, leading to an overwrite of memory beyond the intended buffer. If the X server runs as a privileged user, this could result in privilege escalation, allowing an attacker to gain higher access. If the X server runs as an unprivileged user, it could lead to a denial of service, causing the system to crash.

suse-cvrf
3 дня назад

Security update for libXfont2

suse-cvrf
3 дня назад

Security update for libXfont2