← Vulnerability feed

Vulnerability record · CVE-2026-56001 · published 8 July 2026

CVE-2026-56001: Libxfont heap-based buffer overflow vulnerability

XX · Libxfont

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont

8.8 CVSS 3.1 High EPSS 0.62% · top 52.6% CWE-122 · Heap-based buffer overflow
8.8CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
9 Jul 2026Last modified by NVD

Description

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-56001 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2007-5199Libxfont memory buffer overflow vulnerabilityA single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact.EPSS 2.2%9.3CVE-2013-6462Libxfont memory buffer overflow vulnerabilityStack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to caus…EPSS 10%9.3CVE-2011-2895Freetype memory buffer overflow vulnerabilityThe LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3…EPSS 8.4%8.8CVE-2026-56002Libxfont heap-based buffer overflow vulnerabilityA heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to exec…EPSS 0.56%8.8CVE-2026-56003Libxfont heap-based buffer overflow vulnerabilityA heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXf…EPSS 0.62%8.5CVE-2015-1804Libxfont vulnerabilityThe bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion fo…EPSS 5.0%8.5CVE-2015-1803Canonical ubuntu linux vulnerabilityThe bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps i…EPSS 4.9%8.5CVE-2015-1802Libxfont memory buffer overflow vulnerabilityThe bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote authenticated users to cause a…EPSS 4.9%

Source: NIST National Vulnerability Database (record CVE-2026-56001), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.