Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56002

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7.3

Описание

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

A flaw was found in libXfont2. A specially crafted PCF (Portable Compiled Format) font file, when processed by libXfont2, can lead to a buffer overflow. This occurs because the font parsing process does not properly validate the size of a bitmap buffer against the glyph metrics provided in the malicious font file. An attacker could exploit this vulnerability by providing a malicious font, potentially leading to arbitrary code execution or a denial of service.

Отчет

This is an Important flaw in libXfont2, affecting Red Hat Enterprise Linux. A heap buffer overflow during PCF font file parsing can lead to arbitrary code execution or denial of service. Exploitation requires processing a specially crafted font file, but does not necessitate rendering.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libXfont2Under investigation
Red Hat Enterprise Linux 9libXfont2Under investigation
Red Hat Enterprise Linux 10libXfont2FixedRHSA-2026:4707928.07.2026
Red Hat Enterprise Linux 8libXfont2FixedRHSA-2026:4710328.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2496641libXfont2: PCF Font Parsing Heap Buffer Overflow

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.5
ubuntu
23 дня назад

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

CVSS3: 8.5
nvd
23 дня назад

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

CVSS3: 8.5
msrc
23 дня назад

libXfont2 PCF Font Parsing Heap Buffer Overflow

CVSS3: 8.5
debian
23 дня назад

A heap bufferflow in pcfReadFont() due to missing glyph bounds checkin ...

CVSS3: 8.5
github
23 дня назад

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

7.3 High

CVSS3