CVE-2026-44950Critical· 9.0▾ Midnightfs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 49.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
0.4%
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation.
A malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content.
libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.3-150000.3.6.1libXfont2-2 >= ? < 2.0.7-160000.5.1libXfont2-2 >= ? < 2.0.7-160000.5.1libXfont2-2 >= ? < 2.0.7-160000.5.1libXfont2-2 >= ? < 2.0.7-160000.5.1libXfont2-2 >= ? < 2.0.7-160000.5.1libXfont2-2 >= ? < 2.0.7-160000.5.1libXfont2-2 >= ? < 2.0.7-160000.5.1libXfont2-2 >= ? < 2.0.7-160000.5.1libXfont2-2 >= ? < 2.0.3-3.6.1libXfont2-2 >= ? < 2.0.3-3.6.1libXfont2-2 >= ? < 2.0.3-3.6.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59679Critical· 9.0fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…
CVE-2026-44940Medium· 5.7The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely
CVE-2025-46808Medium· 6.8An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.
CVE-2026-75034High· 7.4A flaw was found in Rancher Manager
CVE-2026-75033High· 7.7A flaw was found in Rancher Manager
CVE-2026-71404High· 8.7A flaw was found in Rancher Manager