Описание
Local attackers with a X connection able to provide PCX fonts to the X
server xorg-server before 21.2.24 and xwayland before 24.1.13 could
cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
A flaw was found in the glamor_font_get() function of the xorg-x11-server. This vulnerability, a heap buffer overflow, occurs when the server processes a specially crafted PCF font file where individual glyph metrics exceed the declared maximum bounds. An authenticated X client can exploit this by loading a malicious font and drawing text, potentially leading to arbitrary code execution with attacker-controlled content and extent. This affects servers utilizing the glamor acceleration backend, such as Xorg with the modesetting driver and Xwayland.
Отчет
This Important flaw in xorg-x11-server allows an authenticated X client to achieve arbitrary code execution. By processing a malicious PCF font file where glyph metrics exceed declared bounds, a heap buffer overflow occurs within the glamor acceleration backend. This vulnerability primarily impacts Red Hat systems running Xorg with the modesetting driver or Xwayland, typically found in desktop environments.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | xorg-x11-server | Not affected | ||
| Red Hat Enterprise Linux 7 | xorg-x11-server | Affected | ||
| Red Hat Enterprise Linux 10 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:38489 | 13.07.2026 |
| Red Hat Enterprise Linux 8 | xorg-x11-server | Fixed | RHSA-2026:38487 | 13.07.2026 |
| Red Hat Enterprise Linux 8 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:38488 | 13.07.2026 |
| Red Hat Enterprise Linux 9 | xorg-x11-server | Fixed | RHSA-2026:38486 | 13.07.2026 |
| Red Hat Enterprise Linux 9 | xorg-x11-server-Xwayland | Fixed | RHSA-2026:38490 | 13.07.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
Local attackers with a X connection able to provide PCX fonts to the X ...
7.5 High
CVSS3