- Package:
- src:libxfont
- Source:
- src:libxfont
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-07-15 12:49:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for libxfont. CVE-2026-56001[0]: | A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before | 2.0.8 due to an overflowing 32bit size could be used by attackers | able to access the X Server to execute code within the X server cont CVE-2026-56002[1]: | A heap bufferflow in pcfReadFont() due to missing glyph bounds | checking in libXfont2 before 2.0.8 allows attackers authenticated | as X client to execute code within the X server. CVE-2026-56003[2]: | A heap buffer overflow due to missing size checking in the property | buffer when parsing PCF files in libXfont2 ComputeScaledProperties() | before libXfont2 before 2.0.8 could be used by attackers using | authenticated X clients to execute code within the X server. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-56001 https://www.cve.org/CVERecord?id=CVE-2026-56001 [1] https://security-tracker.debian.org/tracker/CVE-2026-56002 https://www.cve.org/CVERecord?id=CVE-2026-56002 [2] https://security-tracker.debian.org/tracker/CVE-2026-56003 https://www.cve.org/CVERecord?id=CVE-2026-56003 [3] https://www.openwall.com/lists/oss-security/2026/07/08/1 Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
libxfont, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1141702@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Timo Aaltonen <tjaalton@debian.org> (supplier of updated libxfont package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 09 Jul 2026 21:12:11 +0300
Source: libxfont
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 1:2.0.8-1
Distribution: unstable
Urgency: medium
Maintainer: Debian X Strike Force <debian-x@lists.debian.org>
Changed-By: Timo Aaltonen <tjaalton@debian.org>
Closes: 1141702
Changes:
libxfont (1:2.0.8-1) unstable; urgency=medium
.
* New upstream release. (Closes: #1141702)
- CVE-2026-56001
- CVE-2026-56002
- CVE-2026-56003
* upstream: Add key from Peter Hutterer
Checksums-Sha1:
16b038f06fff923d9c052fe71f1ad8778de3f1c3 2349 libxfont_2.0.8-1.dsc
ff11100a6ed6cd1510a044457236667682bce2ac 677467 libxfont_2.0.8.orig.tar.gz
7663fa64e1da790a70612c3e3a5d948c46b9698d 195 libxfont_2.0.8.orig.tar.gz.asc
fe100a0f5ea8b142e530fc4e5399d420f3e7a9eb 44394 libxfont_2.0.8-1.diff.gz
14c72117056adb604e03e5d3fec5145bb2402753 8365 libxfont_2.0.8-1_source.buildinfo
Checksums-Sha256:
c0373b665b8729d4bd374c8c9b14a43d01c1b8661ff641ae6bf06b201868c3c8 2349 libxfont_2.0.8-1.dsc
a53d621b6ceb1dcbd05a0b9bd7f13c34efa40401cd5c05af904035c567a30f18 677467 libxfont_2.0.8.orig.tar.gz
389848ab99d7db649e28178851795336a8f8204f281a7456ec67917792c1dbce 195 libxfont_2.0.8.orig.tar.gz.asc
11bc77569a0c8aeb6ef798722d99e6d74e24312369d04c80cce10e397efc5080 44394 libxfont_2.0.8-1.diff.gz
9f62170970e753479ecffc5dd7bdc96518a95d1043ce2cf76e1a37bd6fd5f853 8365 libxfont_2.0.8-1_source.buildinfo
Files:
a4dfcbfb432bd4798140f8de955c13cd 2349 x11 optional libxfont_2.0.8-1.dsc
4fc7930ddec112714b9879cabac58a74 677467 x11 optional libxfont_2.0.8.orig.tar.gz
2e2df4d60878daeba4e57c9376846766 195 x11 optional libxfont_2.0.8.orig.tar.gz.asc
6afe04fa58e0f7c86874de3324bf3583 44394 x11 optional libxfont_2.0.8-1.diff.gz
ecc84c270343a997090e574b571cb6ba 8365 x11 optional libxfont_2.0.8-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEdS3ifE3rFwGbS2Yjy3AxZaiJhNwFAmpP5IUACgkQy3AxZaiJ
hNwTfw/+Opq1mqpupFtrMmjC5kws2bLKuXE6aH3CSl5YpxMGPf/6gZ+enR5cyQbl
fSuljZyJJhOwuWJVjA/lRolSrRdy/+ytRs0veC2RvHhvFWMto3shLi+x/iNExD+d
KYyT8u/fy9mhVQ0zNN/XhtNosMMn2G1DEl60JucU1Zt6PC9e+UKprcCBc42M94JD
wSImJLe/dIwfsaLPPszF3HNSshiG0OBrOJ3/qo5jH1IlfHkMpVXQTNmaC9vcYrgu
l0EbSbkXkf3CGAT6rBXf3P8x70y36CbYW3yeTG2xj6f9WT57xmKmd1kqB1M2tucM
vUWoQ14Iey9a7FoK/nVSnJU8GxwWpTCLu8xbM9cF0I4ofw6YImhjF3ht6HLXdS8m
SPQ9N/90pWafEmFb1khc4RBmx8850fqi58ru5ms506nhKHOG6tmPzGtHKRqTCV1M
Utt87PBJZRwVmRD0UYUxWFYQOQj1GCkDqN2RJ8lTXqPyqduR/UC/BqTnp7o45kO1
YtYkioB0c7vHNRgoygc8dj8taBMkuO935dJSnCVz4FRv1CU4sG7pn22dfOglodYe
pTW5z0L39oOnlndGq3h6WUefYGigFEkT3fV3aJ2UKuaP7kludiuc3KtZEUt6Cua2
lt9/CmHtzPN5DMzEwgTnjFCIPutqAJPoHxvdF8aP0e1gNBvJ2XU=
=IE96
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
libxfont, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1141702@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated libxfont package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 10 Jul 2026 14:32:27 +0200
Source: libxfont
Architecture: source
Version: 1:2.0.6-1+deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian X Strike Force <debian-x@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1141702
Changes:
libxfont (1:2.0.6-1+deb13u1) trixie-security; urgency=high
.
* Non-maintainer upload by the Security Team.
* bitscale: fix integer overflow in BitmapScaleBitmaps bytestoalloc
(CVE-2026-56001) (Closes: #1141702)
* pcfread: validate bitmap sizes and offsets against per-glyph metrics
(CVE-2026-56002) (Closes: #1141702)
* bitscale: add bounds check to computeProps for property buffer
(CVE-2026-56003) (Closes: #1141702)
Checksums-Sha1:
36340833ad9b8be9db989076f454a42f45e57e09 2581 libxfont_2.0.6-1+deb13u1.dsc
75bfe18f3c528bfb0de0ec5d10594aa90d609aeb 635826 libxfont_2.0.6.orig.tar.gz
62797fc17e7ba3799a5bacf07d153d5ae65ccb82 801 libxfont_2.0.6.orig.tar.gz.asc
81931f26fffc9c3ac8b7769729ec37954987394b 38890 libxfont_2.0.6-1+deb13u1.diff.gz
0b56bb4c7c15dae227ea42fd31f38d01101bdc13 6431 libxfont_2.0.6-1+deb13u1_source.buildinfo
Checksums-Sha256:
25d131fff652df5f70d16da165ba7f79d360cb52ce5773faa07216036817e7c8 2581 libxfont_2.0.6-1+deb13u1.dsc
a944df7b6837c8fa2067f6a5fc25d89b0acc4011cd0bc085106a03557fb502fc 635826 libxfont_2.0.6.orig.tar.gz
debee1347d3e220968308a87155f7ea517d531a5298e668e54dfab9bf2813d1e 801 libxfont_2.0.6.orig.tar.gz.asc
ed42ef32c50c805cb420c9c96acc61af5ec297658d4e59735ab2e83b96243552 38890 libxfont_2.0.6-1+deb13u1.diff.gz
e18be910a922781865aac0ecc5f196370f9f99c78bd3b52fe9a8e680da33ec21 6431 libxfont_2.0.6-1+deb13u1_source.buildinfo
Files:
752cc5f67d38803a61a52ed4ed8afeb0 2581 x11 optional libxfont_2.0.6-1+deb13u1.dsc
f3dc322ffcf16db5cedccbb41423b2da 635826 x11 optional libxfont_2.0.6.orig.tar.gz
4942e38ca467c1801cfd7407e6687f21 801 x11 optional libxfont_2.0.6.orig.tar.gz.asc
0857e14d77702a7208248c510628c7f2 38890 x11 optional libxfont_2.0.6-1+deb13u1.diff.gz
7d61402d9ed50abd86c205490566569e 6431 x11 optional libxfont_2.0.6-1+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmpT8WVfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89E+nIP/00kwzyvxaOddQk+3xba6Ov9NMdKBpK6
VTqOZF1y5AwwE4VBRCHHAXozbPWfHIX5Xy+2TCK0VMAUtujHqNqQeNXCyHsHsfMI
JjcYkC+1YllKbSLHft2DxCsMdUj/mWtseEfBHaCB6nULfRnlMwAAF6zruDGjN6+I
ImEasCmJyaxCe3ud5cy6cSXjjp7tHEfNOKLWOvFg098kHagfbDVLYUEelTnC2j66
vl9dhpTB9NBxjtcuXLdHpZwQJy0Kyl9KJrdO9VXcTqsk0quvmpEbuuy2WwSpLg3p
iP0wrgdCut2elR2VAajTK4UPaezqTkMJeM+YsIVQ9EVOlNjnX4r5dSNfOfwgtmKV
Mns4eds3Djln/oM1KcdnUHkHbqX4PJNwGWRX023muD0vg+yO+fv3RW1rsTU/QWYF
QyrTF0zQS5rNKuTJL42ZMz/B4ZveDPy7srmO48wkkaa7hZ/3QdDBlxw1CUXqKMGa
lolJ6bVz501i6yWNH2ooAQJqpisHUiGhPJzrNPa9F/Rg43751Y5yIznKg3MVkBft
LmIULz8V2vfJmpJuKuyFOBL5WFaS6WRSdPAcAD7jtDy/zXFwm464SugdTR8sQkvF
PRtWARRV4ChDgbttkX5sLKKERnjI+fOodTcxxN5nFGkagrsdgH7i22Ks5z88/CHl
h+YN9VgACQfy
=GMfo
-----END PGP SIGNATURE-----