---
id: CVE-2026-59679
title: >-
  fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes
  the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16
  reply, but that array was allocated with a size derived from num_extents in
  the…
summary: >-
  fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes
  the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16
  reply, but that array was allocated with a size derived from num_extents in
  the…
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: SUSE
product: libXfont2-2
affected:
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.3-150000.3.6.1
  - libXfont2-2 >= ? < 2.0.7-160000.5.1
  - libXfont2-2 >= ? < 2.0.7-160000.5.1
  - libXfont2-2 >= ? < 2.0.7-160000.5.1
  - libXfont2-2 >= ? < 2.0.7-160000.5.1
  - libXfont2-2 >= ? < 2.0.7-160000.5.1
  - libXfont2-2 >= ? < 2.0.7-160000.5.1
  - libXfont2-2 >= ? < 2.0.7-160000.5.1
  - libXfont2-2 >= ? < 2.0.7-160000.5.1
  - libXfont2-2 >= ? < 2.0.3-3.6.1
  - libXfont2-2 >= ? < 2.0.3-3.6.1
  - libXfont2-2 >= ? < 2.0.3-3.6.1
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:43:03.760'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59679'
references:
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-59679'
    label: meissner@suse.de
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T12:44:48.987855Z'
ingestedAt: '2026-09-12T08:28:09.990Z'
epss: 0.00404
epssPercentile: 0.31795
---

## Overview

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked.
A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
