CVE-2026-59679
9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SUSE | Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Container suse/kiosk/xorg:21.1-83.7 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-Azure | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-Azure-3P | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-BYOS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-BYOS-Azure | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-BYOS-EC2 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-BYOS-GCE | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-EC2 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-GCE | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-Hardened | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-Hardened-Azure | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-Hardened-BYOS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-Hardened-BYOS-Azure | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-Hardened-BYOS-EC2 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-Hardened-BYOS-GCE | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-Hardened-EC2 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAP-Hardened-GCE | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAPCAL | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAPCAL-Azure | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAPCAL-EC2 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP6-SAPCAL-GCE | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-Azure | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-Azure-3P | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-BYOS-Azure | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-BYOS-EC2 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-BYOS-GCE | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-EC2 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-GCE | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-GCE-3P | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-Hardened-Azure | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-Hardened-BYOS-Azure | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-Hardened-BYOS-EC2 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-Hardened-BYOS-GCE | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAP-Hardened-GCE | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAPCAL-Azure | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAPCAL-EC2 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES15-SP7-SAPCAL-GCE | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | Image SLES-SAP-Azure | ? < 2.0.7-160000.5.1 | affected |
| SUSE | Image SLES-SAP-Azure-3P | ? < 2.0.7-160000.5.1 | affected |
| SUSE | Image SLES-SAP-BYOS-Azure | ? < 2.0.7-160000.5.1 | affected |
| SUSE | Image SLES-SAP-BYOS-EC2 | ? < 2.0.7-160000.5.1 | affected |
| SUSE | Image SLES-SAP-BYOS-GCE | ? < 2.0.7-160000.5.1 | affected |
| SUSE | Image SLES-SAP-GCE | ? < 2.0.7-160000.5.1 | affected |
| SUSE | Image SLES-SAP-GCE-3P | ? < 2.0.7-160000.5.1 | affected |
| SUSE | Image SLES-SAPCAL-GCE | ? < 2.0.7-160000.5.1 | affected |
| SUSE | Image SLES12-SP5-Azure-SAP-BYOS | ? < 2.0.3-3.6.1 | affected |
| SUSE | Image SLES12-SP5-Azure-SAP-On-Demand | ? < 2.0.3-3.6.1 | affected |
| SUSE | Image SLES12-SP5-EC2-SAP-BYOS | ? < 2.0.3-3.6.1 | affected |
| SUSE | Image SLES12-SP5-EC2-SAP-On-Demand | ? < 2.0.3-3.6.1 | affected |
| SUSE | Image SLES12-SP5-GCE-SAP-BYOS | ? < 2.0.3-3.6.1 | affected |
| SUSE | Image SLES12-SP5-GCE-SAP-On-Demand | ? < 2.0.3-3.6.1 | affected |
| SUSE | SUSE Liberty Linux 10 | ? < 2.0.6-5.el10_2.3 | affected |
| SUSE | SUSE Liberty Linux 10 | ? < 2.0.6-5.el10_2.3 | affected |
| SUSE | SUSE Liberty Linux 8 | ? < 2.0.3-2.el8_10.3 | affected |
| SUSE | SUSE Liberty Linux 8 | ? < 2.0.3-2.el8_10.3 | affected |
| SUSE | SUSE Liberty Linux 9 | ? < 2.0.3-12.el9_8.3 | affected |
| SUSE | SUSE Liberty Linux 9 | ? < 2.0.3-12.el9_8.3 | affected |
| SUSE | SUSE Linux Enterprise Desktop 15 SP7 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Desktop 15 SP7 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Module for Basesystem 15 SP7 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Module for Basesystem 15 SP7 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server 15 SP7 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server 15 SP7 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server for SAP Applications 15 SP7 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server for SAP Applications 15 SP7 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server 12 SP5-LTSS | ? < 2.0.3-3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server 15 SP4-LTSS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server 15 SP4-LTSS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server 15 SP5-LTSS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server 15 SP5-LTSS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server 15 SP6-LTSS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server 15 SP6-LTSS | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server 16.0 | ? < 2.0.7-160000.5.1 | affected |
| SUSE | SUSE Linux Enterprise Server 16.0 | ? < 2.0.7-160000.5.1 | affected |
| SUSE | SUSE Linux Enterprise Server for SAP applications 16.0 | ? < 2.0.7-160000.5.1 | affected |
| SUSE | SUSE Linux Enterprise Server for SAP applications 16.0 | ? < 2.0.7-160000.5.1 | affected |
| SUSE | SUSE Linux Enterprise Server LTSS Extended Security 12 SP5 | ? < 2.0.3-3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server for SAP Applications 15 SP4 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server for SAP Applications 15 SP4 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server for SAP Applications 15 SP5 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server for SAP Applications 15 SP5 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server for SAP Applications 15 SP6 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Linux Enterprise Server for SAP Applications 15 SP6 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Manager Proxy LTS 4.3 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Manager Proxy LTS 4.3 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Manager Retail Branch Server LTS 4.3 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Manager Retail Branch Server LTS 4.3 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Manager Server LTS 4.3 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | SUSE Manager Server LTS 4.3 | ? < 2.0.3-150000.3.6.1 | affected |
| SUSE | openSUSE Leap 16.0 | ? < 2.0.7-160000.5.1 | affected |
| SUSE | openSUSE Leap 16.0 | ? < 2.0.7-160000.5.1 | affected |
| SUSE | openSUSE Tumbleweed | ? < 2.0.7-3.1 | affected |
| SUSE | openSUSE Tumbleweed | ? < 2.0.7-3.1 | affected |
| SUSE | openSUSE Tumbleweed | ? < 2.0.7-3.1 | affected |
| SUSE | openSUSE Tumbleweed | ? < 2.0.7-3.1 | affected |
| libXfont2 | libXfont2 | ? <= 2.0.8 | affected |
Weaknesses
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.