CVE-2026-59679
Last modified
CVE-2026-59679 is a critical-severity vulnerability rated 9/10 on the CVSS scale. fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| SUSE | Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Container suse/kiosk/xorg:21.1-83.7 | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-Azure | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-Azure-3P | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-BYOS | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-BYOS-Azure | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-BYOS-EC2 | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-BYOS-GCE | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-EC2 | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-GCE | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-Hardened | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-Hardened-Azure | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-Hardened-BYOS | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-Hardened-BYOS-Azure | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-Hardened-BYOS-EC2 | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-Hardened-BYOS-GCE | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-Hardened-EC2 | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAP-Hardened-GCE | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAPCAL | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAPCAL-Azure | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAPCAL-EC2 | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP6-SAPCAL-GCE | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-Azure | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-Azure-3P | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-BYOS-Azure | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-BYOS-EC2 | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-BYOS-GCE | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-EC2 | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-GCE | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-GCE-3P | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-Hardened-Azure | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-Hardened-BYOS-Azure | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-Hardened-BYOS-EC2 | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-Hardened-BYOS-GCE | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAP-Hardened-GCE | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAPCAL-Azure | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAPCAL-EC2 | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES15-SP7-SAPCAL-GCE | >= ?, < 2.0.3-150000.3.6.1 |
| SUSE | Image SLES-SAP-Azure | >= ?, < 2.0.7-160000.5.1 |
| SUSE | Image SLES-SAP-Azure-3P | >= ?, < 2.0.7-160000.5.1 |
| SUSE | Image SLES-SAP-BYOS-Azure | >= ?, < 2.0.7-160000.5.1 |
| SUSE | Image SLES-SAP-BYOS-EC2 | >= ?, < 2.0.7-160000.5.1 |
| SUSE | Image SLES-SAP-BYOS-GCE | >= ?, < 2.0.7-160000.5.1 |
| SUSE | Image SLES-SAP-GCE | >= ?, < 2.0.7-160000.5.1 |
| SUSE | Image SLES-SAP-GCE-3P | >= ?, < 2.0.7-160000.5.1 |
| SUSE | Image SLES-SAPCAL-GCE | >= ?, < 2.0.7-160000.5.1 |
| SUSE | Image SLES12-SP5-Azure-SAP-BYOS | >= ?, < 2.0.3-3.6.1 |
| SUSE | Image SLES12-SP5-Azure-SAP-On-Demand | >= ?, < 2.0.3-3.6.1 |
| SUSE | Image SLES12-SP5-EC2-SAP-BYOS | >= ?, < 2.0.3-3.6.1 |
Showing 50 of 80 affected configurations. See the CNA advisory for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-59679?
How severe is CVE-2026-59679?
How do I fix CVE-2026-59679?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5967ThreatSonar Anti-Ransomware developed by TeamT5 has an Privi…8.8
- CVE-2026-59674A UNIX Symbolic Link (Symlink) Following vulnerability in op…7.1
- CVE-2026-59675When API audit logging is enabled, the middleware reads the …7.5
- CVE-2026-59676A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerab…5.8
- CVE-2026-59677A Missing Authorization vulnerability in selinux policycoreu…6.8
- CVE-2026-59678An Incorrect Authorization vulnerability in Linux-Gaming Por…7.1
- CVE-2026-5968Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-59680An OS command injection vulnerability was found in yast2-use…8
- CVE-2026-59681A OS command injection vulnerability in yast2-auth-client al…8.8
- CVE-2026-59682Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB…9.1
- CVE-2026-59683The OpenRGB network protocol allows to write attacker contro…9.8
- CVE-2026-59686An OS Command Injection vulnerability in Progress Software L…8.4
Are you affected by CVE-2026-59679?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
