AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-55999

HIGH · CVSS 8.5 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

Local attackers with X connection access can exploit a heap buffer overflow vulnerability in the xorg-server and xwayland components, affecting versions prior to 21.2.24 and 24.1.13, respectively. This flaw arises from inadequate glyph boundary checks when handling PCX fonts, potentially allowing attackers to execute arbitrary code. Organizations using these X server implementations should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-55999
Severity
HIGH
CVSS
8.5
EPSS
0.27%

Original NVD Description

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

Related CVEs

Other vulnerabilities affecting the same vendor(s)