CVE-2026-56003: X Libxfont
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.
Affected products
- X Libxfont: from 2.0.0, before 2.0.8 (fixed in 2.0.8)
Published 2026-07-08. Last modified 2026-07-09.