CVE-2026-44950

Summary

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation.

A malicious font server can send overlapping source offsets – for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content.

Affected Software

VendorProductVersion RangeStatus
SUSEContainer suse/kiosk/tigervnc-x11vnc:1.14-63.8? < 2.0.3-150000.3.6.1affected
SUSEContainer suse/kiosk/xorg:21.1-83.7? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-Azure? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-Azure-3P? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-BYOS? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-BYOS-Azure? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-BYOS-EC2? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-BYOS-GCE? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-EC2? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-GCE? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-Hardened? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-Hardened-Azure? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-Hardened-BYOS? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-Hardened-BYOS-Azure? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-Hardened-BYOS-EC2? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-Hardened-BYOS-GCE? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-Hardened-EC2? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAP-Hardened-GCE? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAPCAL? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAPCAL-Azure? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAPCAL-EC2? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP6-SAPCAL-GCE? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-Azure? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-Azure-3P? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-BYOS-Azure? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-BYOS-EC2? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-BYOS-GCE? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-EC2? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-GCE? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-GCE-3P? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-Hardened-Azure? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-Hardened-BYOS-Azure? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-Hardened-BYOS-EC2? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-Hardened-BYOS-GCE? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAP-Hardened-GCE? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAPCAL-Azure? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAPCAL-EC2? < 2.0.3-150000.3.6.1affected
SUSEImage SLES15-SP7-SAPCAL-GCE? < 2.0.3-150000.3.6.1affected
SUSEImage SLES-SAP-Azure? < 2.0.7-160000.5.1affected
SUSEImage SLES-SAP-Azure-3P? < 2.0.7-160000.5.1affected
SUSEImage SLES-SAP-BYOS-Azure? < 2.0.7-160000.5.1affected
SUSEImage SLES-SAP-BYOS-EC2? < 2.0.7-160000.5.1affected
SUSEImage SLES-SAP-BYOS-GCE? < 2.0.7-160000.5.1affected
SUSEImage SLES-SAP-GCE? < 2.0.7-160000.5.1affected
SUSEImage SLES-SAP-GCE-3P? < 2.0.7-160000.5.1affected
SUSEImage SLES-SAPCAL-GCE? < 2.0.7-160000.5.1affected
SUSEImage SLES12-SP5-Azure-SAP-BYOS? < 2.0.3-3.6.1affected
SUSEImage SLES12-SP5-Azure-SAP-On-Demand? < 2.0.3-3.6.1affected
SUSEImage SLES12-SP5-EC2-SAP-BYOS? < 2.0.3-3.6.1affected
SUSEImage SLES12-SP5-EC2-SAP-On-Demand? < 2.0.3-3.6.1affected
SUSEImage SLES12-SP5-GCE-SAP-BYOS? < 2.0.3-3.6.1affected
SUSEImage SLES12-SP5-GCE-SAP-On-Demand? < 2.0.3-3.6.1affected
SUSESUSE Liberty Linux 10? < 2.0.6-5.el10_2.3affected
SUSESUSE Liberty Linux 10? < 2.0.6-5.el10_2.3affected
SUSESUSE Liberty Linux 8? < 2.0.3-2.el8_10.3affected
SUSESUSE Liberty Linux 8? < 2.0.3-2.el8_10.3affected
SUSESUSE Liberty Linux 9? < 2.0.3-12.el9_8.3affected
SUSESUSE Liberty Linux 9? < 2.0.3-12.el9_8.3affected
SUSESUSE Linux Enterprise Desktop 15 SP7? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Desktop 15 SP7? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Module for Basesystem 15 SP7? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Module for Basesystem 15 SP7? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server 15 SP7? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server 15 SP7? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server for SAP Applications 15 SP7? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server for SAP Applications 15 SP7? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise High Performance Computing 15 SP4-LTSS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise High Performance Computing 15 SP4-LTSS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise High Performance Computing 15 SP5-LTSS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise High Performance Computing 15 SP5-LTSS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server 12 SP5-LTSS? < 2.0.3-3.6.1affected
SUSESUSE Linux Enterprise Server 15 SP4-LTSS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server 15 SP4-LTSS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server 15 SP5-LTSS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server 15 SP5-LTSS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server 15 SP6-LTSS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server 15 SP6-LTSS? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server 16.0? < 2.0.7-160000.5.1affected
SUSESUSE Linux Enterprise Server 16.0? < 2.0.7-160000.5.1affected
SUSESUSE Linux Enterprise Server for SAP applications 16.0? < 2.0.7-160000.5.1affected
SUSESUSE Linux Enterprise Server for SAP applications 16.0? < 2.0.7-160000.5.1affected
SUSESUSE Linux Enterprise Server LTSS Extended Security 12 SP5? < 2.0.3-3.6.1affected
SUSESUSE Linux Enterprise Server for SAP Applications 15 SP4? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server for SAP Applications 15 SP4? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server for SAP Applications 15 SP5? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server for SAP Applications 15 SP5? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server for SAP Applications 15 SP6? < 2.0.3-150000.3.6.1affected
SUSESUSE Linux Enterprise Server for SAP Applications 15 SP6? < 2.0.3-150000.3.6.1affected
SUSESUSE Manager Proxy LTS 4.3? < 2.0.3-150000.3.6.1affected
SUSESUSE Manager Proxy LTS 4.3? < 2.0.3-150000.3.6.1affected
SUSESUSE Manager Retail Branch Server LTS 4.3? < 2.0.3-150000.3.6.1affected
SUSESUSE Manager Retail Branch Server LTS 4.3? < 2.0.3-150000.3.6.1affected
SUSESUSE Manager Server LTS 4.3? < 2.0.3-150000.3.6.1affected
SUSESUSE Manager Server LTS 4.3? < 2.0.3-150000.3.6.1affected
SUSEopenSUSE Leap 16.0? < 2.0.7-160000.5.1affected
SUSEopenSUSE Leap 16.0? < 2.0.7-160000.5.1affected
SUSEopenSUSE Tumbleweed? < 2.0.7-3.1affected
SUSEopenSUSE Tumbleweed? < 2.0.7-3.1affected
SUSEopenSUSE Tumbleweed? < 2.0.7-3.1affected
SUSEopenSUSE Tumbleweed? < 2.0.7-3.1affected
libXfontlibXfont? <= 2.0.8affected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References