Synopsis:
libXfont2 security updateSummary:
An update for libXfont2 is now available for openEuler-22.03-LTS-SP4,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-24.03-LTS-SP4,openEuler-20.03-LTS-SP4Description:
libXfont provides the core of the legacy X11 font system, handling the index files (fonts.dir, fonts.alias, fonts.scale), the various font file formats, and rasterizing them. contains runtime library.
Security Fix(es):
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server context.(CVE-2026-56001)
A heap buffer overflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server.(CVE-2026-56002)
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.(CVE-2026-56003)Topic:
An update for libXfont2 is now available for openEuler-22.03-LTS-SP4,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-24.03-LTS-SP4,openEuler-20.03-LTS-SP4.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.Severity:
HighAffected Component:
libXfont2
2.0.4-2.oe2003sp42.0.4-2.oe2003sp42.0.4-2.oe2003sp42.0.4-2.oe2003sp42.0.4-2.oe2003sp42.0.5-5.oe2203sp42.0.5-5.oe2203sp42.0.5-5.oe2203sp42.0.5-5.oe2203sp42.0.5-5.oe2203sp4Exploitability
AV:NAC:HPR:LUI:NScope
S:CImpact
C:HI:HA:H8.5/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H