Heap Buffer Overflow in libXfont2 Affects Font Server Client
CVE-2026-44950

9.5CRITICAL

What is CVE-2026-44950?

A heap buffer overflow exists in the libXfont2 font-server client due to insufficient validation of destination buffer sizes when processing glyph bitmaps. The fs_read_glyphs() function in src/fc/fserve.c does not adequately verify whether the cumulative write operations exceed the allocated memory for the destination buffer. This flaw allows a malicious font server to exploit overlapping source offsets, potentially leading to arbitrary memory modifications through crafted font data.

Affected Version(s)

Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 ? < 2.0.3-150000.3.6.1

Container suse/kiosk/xorg:21.1-83.7 ? < 2.0.3-150000.3.6.1

Image SLES-SAP-Azure ? < 2.0.7-160000.5.1

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zx (Jace)
.