Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55999

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

A flaw was found in the glamor_font_get() function of the xorg-x11-server. This vulnerability, a heap buffer overflow, occurs when the server processes a specially crafted PCF font file where individual glyph metrics exceed the declared maximum bounds. An authenticated X client can exploit this by loading a malicious font and drawing text, potentially leading to arbitrary code execution with attacker-controlled content and extent. This affects servers utilizing the glamor acceleration backend, such as Xorg with the modesetting driver and Xwayland.

Отчет

This Important flaw in xorg-x11-server allows an authenticated X client to achieve arbitrary code execution. By processing a malicious PCF font file where glyph metrics exceed declared bounds, a heap buffer overflow occurs within the glamor acceleration backend. This vulnerability primarily impacts Red Hat systems running Xorg with the modesetting driver or Xwayland, typically found in desktop environments.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverNot affected
Red Hat Enterprise Linux 7xorg-x11-serverAffected
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2026:3848913.07.2026
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2026:3848713.07.2026
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2026:3848813.07.2026
Red Hat Enterprise Linux 9xorg-x11-serverFixedRHSA-2026:3848613.07.2026
Red Hat Enterprise Linux 9xorg-x11-server-XwaylandFixedRHSA-2026:3849013.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=2496165xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.5
ubuntu
23 дня назад

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

CVSS3: 8.5
nvd
23 дня назад

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

msrc
23 дня назад

xorg-server / xwayland glamor font atlas Heap Buffer Overflow

CVSS3: 8.5
debian
23 дня назад

Local attackers with a X connection able to provide PCX fonts to the X ...

suse-cvrf
23 дня назад

Security update for xorg-x11-server

7.5 High

CVSS3