{"id":"CVE-2026-59679","title":"fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…","summary":"fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…","severity":"critical","cvss":9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-787"],"vendor":"SUSE","product":"libXfont2-2","affected":["libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.3-150000.3.6.1","libXfont2-2 >= ? < 2.0.7-160000.5.1","libXfont2-2 >= ? < 2.0.7-160000.5.1","libXfont2-2 >= ? < 2.0.7-160000.5.1","libXfont2-2 >= ? < 2.0.7-160000.5.1","libXfont2-2 >= ? < 2.0.7-160000.5.1","libXfont2-2 >= ? < 2.0.7-160000.5.1","libXfont2-2 >= ? < 2.0.7-160000.5.1","libXfont2-2 >= ? < 2.0.7-160000.5.1","libXfont2-2 >= ? < 2.0.3-3.6.1","libXfont2-2 >= ? < 2.0.3-3.6.1","libXfont2-2 >= ? < 2.0.3-3.6.1"],"published":"2026-09-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T15:43:03.760","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59679","references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-59679","label":"meissner@suse.de"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-10T12:44:48.987855Z"},"ingestedAt":"2026-09-12T08:28:09.990Z","epss":0.00411,"epssPercentile":0.35033,"slug":"CVE-2026-59679","body":"## Overview\n\nfs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked.\nA malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":49.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}