Junglewise Threat Intelligence

CVE-2026-44950: X.Org libXfont2 heap buffer overflow in fs_read_glyphs

CVE-2026-44950 · Severity: critical · CVSS 9 · Published 2026-09-10

Technologies: X.Org libXfont2. Vendors: X.Org.

Executive brief

libXfont2 is a font handling library used by X Window System servers and clients to render text and manage font resources. A malicious font server can exploit incomplete bounds checking in the glyph-reading function to write excessive data into a small heap buffer, potentially allowing remote code execution or a denial-of-service attack against any application using the library to connect to a compromised font server.

Technical details

The fs_read_glyphs() function in libXfont2 (src/fc/fserve.c) contains a heap buffer overflow vulnerability. The function copies glyph bitmap data into a pre-allocated buffer but only validates that each individual source glyph's range (position and length) lies within the source bitmap. It fails to check whether the cumulative destination writes exceed the allocated buffer size. A malicious font server can send multiple glyph records with overlapping source offsets—for example, 1000 glyphs each referencing {position:0, length:64}—causing 64KB of data to be written into a 64-byte buffer. The attack is network-reachable and requires no authentication; the attacker must control the font server. This leads to heap corruption with attacker-controlled content, enabling code execution or denial of service.

Affected products

  • X.Org libXfont2 <UNKNOWN>

Timeline

  • 2026-09-10: disclosed

References

Related threats