{"id":"CVE-2026-56002","title":"A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.","summary":"A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.","severity":"high","cvss":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"x","product":"libxfont","affected":["libxfont < 2.0.8"],"patched":["libxfont 2.0.8"],"published":"2026-07-08","updated":"2026-07-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56002","references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bb27b1439968811a3674","label":"meissner@suse.de"},{"url":"https://www.openwall.com/lists/oss-security/2026/07/08/1","label":"meissner@suse.de"}],"tags":["nvd"],"epss":0.00428,"epssPercentile":0.36651,"ingestedAt":"2026-07-13T14:27:26.818Z","slug":"CVE-2026-56002","body":"## Overview\n\nA heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.\n\n## Affected\n\n- `libxfont < 2.0.8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `libxfont 2.0.8`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}