CVE-2026-56003: X Libxfont

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.

Affected products

  • X Libxfont: from 2.0.0, before 2.0.8 (fixed in 2.0.8)

Published 2026-07-08. Last modified 2026-07-09.