CVE-2026-56002: X Libxfont

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

Affected products

  • X Libxfont: before 2.0.8 (fixed in 2.0.8)

Published 2026-07-08. Last modified 2026-07-13.