[CLSA-2026:1787150510] libXfont2: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-19 14:42:02 UTC
Description:
- Fix CVE-2026-59679: out-of-bounds read/write in fs_read_glyphs due to num_chars not being validated against the allocated encoding array size in fserve.c (upstream commit 668fea81f40bcb48ec67fb55d0b851049d265290) - Fix CVE-2026-44950: heap buffer overflow in fs_read_glyphs due to a missing bounds check on cumulative glyph data writes into the allbits buffer in fserve.c (upstream commit c2d222bb22c623d8a40f3275077fc7e6617f2c8a)
Updated packages:
  • libXfont2-2.0.3-12.el9_2.tuxcare.els4.i686.rpm
    sha:42c9cba9a320b0ca284ecc9ca6da408acc97d7112838623de071ea47062fd485
  • libXfont2-2.0.3-12.el9_2.tuxcare.els4.x86_64.rpm
    sha:7b576bfbf40b243ebeb7a2d36f178991774490d4e2910bc36f0a6b7f8683e10b
  • libXfont2-devel-2.0.3-12.el9_2.tuxcare.els4.i686.rpm
    sha:f211bb82d8018af75d697c8abd48405874aca907e8f91648781b6760ab894ca0
  • libXfont2-devel-2.0.3-12.el9_2.tuxcare.els4.x86_64.rpm
    sha:8e3e7e328a06c8b69a6c648b6a66f9482bb347190c5f57004d84d618a05eec49
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.