Release date:
2026-08-26 09:32:20 UTC
Description:
- CVE-2026-59679: validate num_chars against the encoding array size in
fs_read_glyphs() in src/fc/fserve.c; prevents an out-of-bounds read/write on
encoding[] when a font server sends more glyphs than extents
(upstream commit 668fea81f40bcb48ec67fb55d0b851049d265290)
- CVE-2026-44950: bounds-check cumulative glyph data writes in fs_read_glyphs()
in src/fc/fserve.c; prevents a heap buffer overflow from overlapping source
offsets whose total length exceeds the allocated bitmap buffer
(upstream commit c2d222bb22c623d8a40f3275077fc7e6617f2c8a)
Updated packages:
-
libXfont2-2.0.3-12.el9_6.tuxcare.els4.i686.rpm
sha:b6836fc0dac02f60f514c7daf060170f58fbd88a45f61b926c50eb90b9ccb2ab
-
libXfont2-2.0.3-12.el9_6.tuxcare.els4.x86_64.rpm
sha:c25606a623c815626f5da53b25b2d865c435c64b8aa6f22624d7bf963dcf225c
-
libXfont2-devel-2.0.3-12.el9_6.tuxcare.els4.i686.rpm
sha:06dfbda7da272c5084dc361d0657936dcd07a2a305b4d67cb4fedfafceb48583
-
libXfont2-devel-2.0.3-12.el9_6.tuxcare.els4.x86_64.rpm
sha:c4a5a0d353f6316ae056d85323f7d9cfa15b03573f743ec7fbb3f722e80c2b77
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.