CVE-2026-44950: Buffer Overflow
fsreadglyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap data into a single allbits buffer allocated to rep->nbytes bytes. The per-glyph validation checks only that each source slice (position, length) lies within the source bitmap buffer, but never checks whether the cumulative destination writes exceed the allocation. A malicious font server can send overlapping source offsets (e.g. 1000 glyphs each referencing {position:0, length:64} with nbytes=64) so that each individual source range passes validation, but the cumulative writes total 64000 bytes into a 64-byte heap buffer. This is a heap buffer overflow with attacker-controlled content and size. When the X server runs as root, this can lead to privilege escalation. When it runs as an unprivileged user, this results in a denial of service (crash).
This is caused by an incomplete fix of CVE-2014-0210.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libXfont2 (font-server)to a version that resolves this vulnerability.Patch CVE-2014-0210 - Compensating control
Run the X server/font server components without elevated privileges (avoid running the X server as root) to reduce impact from the privilege-escalation path; when run as an unprivileged user it results only in denial of service (crash).