Vulnary
← back to the feed
Critical· 9.2

CVE-2026-59679

A flaw in the libXfont2 font-server client allows a malicious font server to send mismatched data, causing the client to read or write memory outside its intended bounds. The issue arises when the server reports a small number of extents but a large number of character bitmaps, leading to an out-of-bounds heap access. This can be exploited remotely without authentication.

publishedSep 10, 2026
last modifiedSep 10, 2026
sourcesNVD
severity · cvss
9.2
critical · how bad it is
exploitation · epss
<1%
35th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 25, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

The libXfont2 font-server client used in X11 environments, typically on Linux and Unix systems that rely on X11 font services.

02

Real-world impact

An attacker can read sensitive data from the client’s memory or corrupt it, potentially leading to arbitrary code execution or system compromise.

03

Why this severity

The CVSS score of 9.2 reflects the high impact of confidentiality, integrity, and availability loss, combined with the fact that the vulnerability can be triggered remotely by an unauthenticated attacker with no special privileges.

04

What to do about it

no official fix yet

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityHigh
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-59679: A flaw in the libXfont2 font-server client allows a malicious font ser · Vulnary