[CLSA-2026:1787162017] libXfont2: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-26 09:32:20 UTC
Description:
- CVE-2026-59679: validate num_chars against the encoding array size in fs_read_glyphs() in src/fc/fserve.c; prevents an out-of-bounds read/write on encoding[] when a font server sends more glyphs than extents (upstream commit 668fea81f40bcb48ec67fb55d0b851049d265290) - CVE-2026-44950: bounds-check cumulative glyph data writes in fs_read_glyphs() in src/fc/fserve.c; prevents a heap buffer overflow from overlapping source offsets whose total length exceeds the allocated bitmap buffer (upstream commit c2d222bb22c623d8a40f3275077fc7e6617f2c8a)
Updated packages:
  • libXfont2-2.0.3-12.el9_6.tuxcare.els4.i686.rpm
    sha:b6836fc0dac02f60f514c7daf060170f58fbd88a45f61b926c50eb90b9ccb2ab
  • libXfont2-2.0.3-12.el9_6.tuxcare.els4.x86_64.rpm
    sha:c25606a623c815626f5da53b25b2d865c435c64b8aa6f22624d7bf963dcf225c
  • libXfont2-devel-2.0.3-12.el9_6.tuxcare.els4.i686.rpm
    sha:06dfbda7da272c5084dc361d0657936dcd07a2a305b4d67cb4fedfafceb48583
  • libXfont2-devel-2.0.3-12.el9_6.tuxcare.els4.x86_64.rpm
    sha:c4a5a0d353f6316ae056d85323f7d9cfa15b03573f743ec7fbb3f722e80c2b77
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.