Heap Overflow Vulnerability in libXfont2 Affecting X.Org Foundation
CVE-2026-59679

9.2CRITICAL

What is CVE-2026-59679?

The fs_read_glyphs() function in the libXfont2 font-server client contains a flaw whereby the per-character encoding[] array is indexed using num_chars from the FS_QueryXBitmaps16 reply. However, this array's size is derived from num_extents in the FS_QueryXExtents16 reply, leading to a lack of cross-verification between these parameters. An attacker controlling a malicious font server could exploit this oversight by returning a small num_extents value (e.g., 1) while simultaneously sending a larger num_chars value (e.g., 100000) in the bitmaps reply, resulting in out-of-bounds reads and writes that could be exploited to manipulate the affected system's memory.

Affected Version(s)

Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 ? < 2.0.3-150000.3.6.1

Container suse/kiosk/xorg:21.1-83.7 ? < 2.0.3-150000.3.6.1

Image SLES-SAP-Azure ? < 2.0.7-160000.5.1

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zx (Jace)
.