CVE-2026-59679

CRITICALCVSS 9/10EPSS 0.41%

Last modified

CVE-2026-59679 is a critical-severity vulnerability rated 9/10 on the CVSS scale. fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. EPSS estimates a 0.41% chance of exploitation in the next 30 days.

Description

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
SUSEContainer suse/kiosk/tigervnc-x11vnc:1.14-63.8>= ?, < 2.0.3-150000.3.6.1
SUSEContainer suse/kiosk/xorg:21.1-83.7>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-Azure>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-Azure-3P>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-BYOS>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-BYOS-Azure>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-BYOS-EC2>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-BYOS-GCE>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-EC2>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-GCE>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-Hardened>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-Hardened-Azure>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-Hardened-BYOS>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-Hardened-BYOS-Azure>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-Hardened-BYOS-EC2>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-Hardened-BYOS-GCE>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-Hardened-EC2>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAP-Hardened-GCE>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAPCAL>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAPCAL-Azure>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAPCAL-EC2>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP6-SAPCAL-GCE>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-Azure>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-Azure-3P>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-BYOS-Azure>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-BYOS-EC2>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-BYOS-GCE>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-EC2>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-GCE>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-GCE-3P>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-Hardened-Azure>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-Hardened-BYOS-Azure>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-Hardened-BYOS-EC2>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-Hardened-BYOS-GCE>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAP-Hardened-GCE>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAPCAL-Azure>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAPCAL-EC2>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES15-SP7-SAPCAL-GCE>= ?, < 2.0.3-150000.3.6.1
SUSEImage SLES-SAP-Azure>= ?, < 2.0.7-160000.5.1
SUSEImage SLES-SAP-Azure-3P>= ?, < 2.0.7-160000.5.1
SUSEImage SLES-SAP-BYOS-Azure>= ?, < 2.0.7-160000.5.1
SUSEImage SLES-SAP-BYOS-EC2>= ?, < 2.0.7-160000.5.1
SUSEImage SLES-SAP-BYOS-GCE>= ?, < 2.0.7-160000.5.1
SUSEImage SLES-SAP-GCE>= ?, < 2.0.7-160000.5.1
SUSEImage SLES-SAP-GCE-3P>= ?, < 2.0.7-160000.5.1
SUSEImage SLES-SAPCAL-GCE>= ?, < 2.0.7-160000.5.1
SUSEImage SLES12-SP5-Azure-SAP-BYOS>= ?, < 2.0.3-3.6.1
SUSEImage SLES12-SP5-Azure-SAP-On-Demand>= ?, < 2.0.3-3.6.1
SUSEImage SLES12-SP5-EC2-SAP-BYOS>= ?, < 2.0.3-3.6.1

Showing 50 of 80 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-59679?
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.
How severe is CVE-2026-59679?
CVE-2026-59679 has a CVSS score of 9/10 (CRITICAL severity). The EPSS model estimates a 0.41% probability of exploitation in the next 30 days.
How do I fix CVE-2026-59679?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-59679?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST