CVE-2026-56002: X Libxfont
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server.
Affected products
- X Libxfont: before 2.0.8 (fixed in 2.0.8)
Published 2026-07-08. Last modified 2026-07-13.