Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55999

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

A flaw was found in the glamor_font_get() function of the xorg-x11-server. This vulnerability, a heap buffer overflow, occurs when the server processes a specially crafted PCF font file where individual glyph metrics exceed the declared maximum bounds. An authenticated X client can exploit this by loading a malicious font and drawing text, potentially leading to arbitrary code execution with attacker-controlled content and extent. This affects servers utilizing the glamor acceleration backend, such as Xorg with the modesetting driver and Xwayland.

Отчет

This Important flaw in xorg-x11-server allows an authenticated X client to achieve arbitrary code execution. By processing a malicious PCF font file where glyph metrics exceed declared bounds, a heap buffer overflow occurs within the glamor acceleration backend. This vulnerability primarily impacts Red Hat systems running Xorg with the modesetting driver or Xwayland, typically found in desktop environments.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverNot affected
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2026:3848913.07.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportxorg-x11-server-XwaylandFixedRHSA-2026:5010004.08.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-serverFixedRHSA-2026:5011704.08.2026
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2026:3848713.07.2026
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2026:3848813.07.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportxorg-x11-serverFixedRHSA-2026:4960603.08.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onxorg-x11-serverFixedRHSA-2026:4960603.08.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportxorg-x11-serverFixedRHSA-2026:4960503.08.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportxorg-x11-server-XwaylandFixedRHSA-2026:5345011.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=2496165xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow

EPSS

Процентиль: 19%
0.00269
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.5
ubuntu
2 месяца назад

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

CVSS3: 8.5
nvd
2 месяца назад

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

msrc
2 месяца назад

xorg-server / xwayland glamor font atlas Heap Buffer Overflow

CVSS3: 8.5
debian
2 месяца назад

Local attackers with a X connection able to provide PCX fonts to the X ...

suse-cvrf
2 месяца назад

Security update for xorg-x11-server

EPSS

Процентиль: 19%
0.00269
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-55999