Описание
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont
A flaw was found in libXfont2. In the BitmapScaleBitmaps() function, an integer overflow can occur when calculating the memory needed for font glyphs. This overflow leads to a heap buffer overflow, where a smaller-than-required memory buffer is allocated. A local attacker can exploit this by loading a specially crafted PCF font, potentially leading to arbitrary code execution or a denial of service.
Отчет
This flaw in libXfont2 is rated as Important. A local attacker could exploit an integer overflow in the BitmapScaleBitmaps() function, leading to a heap buffer overflow and potential arbitrary code execution or denial of service. This vulnerability requires the processing of a specially crafted PCF font, typically through an X server or an application configured to load untrusted font files.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 7 | libXfont2 | Affected | ||
| Red Hat Enterprise Linux 9 | libXfont2 | Affected | ||
| Red Hat Enterprise Linux 10 | libXfont2 | Fixed | RHSA-2026:47079 | 28.07.2026 |
| Red Hat Enterprise Linux 8 | libXfont2 | Fixed | RHSA-2026:47103 | 28.07.2026 |
Показывать по
Дополнительная информация
Статус:
7.3 High
CVSS3
Связанные уязвимости
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont
libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 ...
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont
7.3 High
CVSS3