AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-56002

HIGH · CVSS 8.5 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A heap buffer overflow vulnerability in the pcfReadFont() function of libXfont2 prior to version 2.0.8 allows authenticated X clients to execute arbitrary code within the X server due to inadequate glyph bounds checking. This poses a significant risk to systems utilizing affected versions of libXfont2, particularly in environments where X clients are deployed. Organizations using this library should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-56002
Severity
HIGH
CVSS
8.5
EPSS
0.43%

Original NVD Description

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

Related CVEs

Other vulnerabilities affecting the same vendor(s)