Vulnerability Description
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| X | Libxfont | < 2.0.8 |
Related Weaknesses (CWE)
References
- https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bbPatch
- https://www.openwall.com/lists/oss-security/2026/07/08/1Mailing ListPatchThird Party Advisory
FAQ
What is CVE-2026-56002?
CVE-2026-56002 is a vulnerability with a CVSS score of 8.5 (HIGH). A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server.
How severe is CVE-2026-56002?
CVE-2026-56002 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56002?
Check the references section above for vendor advisories and patch information. Affected products include: X Libxfont.