Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44950

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in the libXfont2 font-server client. This heap buffer overflow vulnerability allows a malicious font server to send specially crafted glyph data. The fs_read_glyphs() function fails to properly validate the total size of the incoming data, leading to an overwrite of memory beyond the intended buffer. If the X server runs as a privileged user, this could result in privilege escalation, allowing an attacker to gain higher access. If the X server runs as an unprivileged user, it could lead to a denial of service, causing the system to crash.

Отчет

This is an Important flaw. A heap buffer overflow in the libXfont2 font server client can be triggered by a malicious font server. If the X server runs as root, this could lead to privilege escalation; otherwise, it results in a denial of service. Red Hat Enterprise Linux typically runs the X server as an unprivileged user, mitigating the privilege escalation risk but still allowing for denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libXfont2Affected
Red Hat Enterprise Linux 7libXfont2Affected
Red Hat Enterprise Linux 8libXfont2Affected
Red Hat Enterprise Linux 9libXfont2Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2509622libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client

7.5 High

CVSS3

Связанные уязвимости

ubuntu
4 дня назад

[Font Server Client Cumulative Glyph Data Heap Buffer Overflow]

debian

[Font Server Client Cumulative Glyph Data Heap Buffer Overflow]

suse-cvrf
3 дня назад

Security update for libXfont2

suse-cvrf
3 дня назад

Security update for libXfont2

7.5 High

CVSS3