Описание
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Отчет
Red Hat rates this issue as Important impact. In xorg-x11-server and xorg-x11-server-Xwayland, the X server allocates a 256-byte stack buffer for font alias resolution but libXfont2 permits alias target names up to 1024 bytes. A local X client requesting a font alias between 257 and 1023 bytes triggers a stack buffer overflow. Any local user who can connect to the X server display can attempt exploitation. This may crash the display server or, where the X server runs with elevated privileges, could contribute to local privilege escalation. Upstream fixed this in xorg-server 21.1.23 and xwayland 24.1.12.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | tigervnc | Affected | ||
| Red Hat Enterprise Linux 6 | xorg-x11-server | Out of support scope | ||
| Red Hat Enterprise Linux 10 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:26566 | 22.06.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | xorg-x11-server-Xwayland | Fixed | RHSA-2026:36798 | 08.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | xorg-x11-server | Fixed | RHSA-2026:36083 | 07.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | tigervnc | Fixed | RHSA-2026:46473 | 27.07.2026 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:26562 | 17.06.2026 |
| Red Hat Enterprise Linux 8 | xorg-x11-server | Fixed | RHSA-2026:26709 | 17.06.2026 |
| Red Hat Enterprise Linux 8 | tigervnc | Fixed | RHSA-2026:28923 | 24.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | xorg-x11-server | Fixed | RHSA-2026:36792 | 08.07.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch
A stack-based buffer overflow flaw was found in the X.Org X server and ...
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
EPSS
7.8 High
CVSS3