CVE-2026-56003
ubuntu libxfont: Heap-basierter Pufferueberlauf
Affected
- ubuntu/libxfont
1:2.0.3-1ubuntu0.1~esm2..* - ubuntu/libxfont
1:2.0.3-1ubuntu0.20.04.1~esm2..* - ubuntu/libxfont
1:2.0.5-1ubuntu0.2..* - ubuntu/libxfont
1:2.0.6-1+deb13u1build0.24.04.2..* - ubuntu/libxfont
1:2.0.6-2ubuntu0.2..* - ubuntu/libxfont
1:1.4.7-1ubuntu0.4+esm2..* - ubuntu/libxfont
1:1.5.1-1ubuntu0.16.04.4+esm2..*
Description
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.
Affected operating systems
linux
ubuntu / libxfontbionic
linux
ubuntu / libxfontfocal
linux
ubuntu / libxfontjammy
linux
ubuntu / libxfontnoble
linux
ubuntu / libxfontresolute
linux
ubuntu / libxfonttrusty
linux
ubuntu / libxfontxenial
Metrics
Show all metrics
Weakness classes (CWE)
CWE-122Variant
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-07-08 10:16 UTC· meissner@suse.de
- Affected: libXfont2
- Description: A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.
- CVSS V3.1: AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-122