RHSA-2026:61390: Important: libXfont2 security update
Published Aug 31, 2026
·Updated
X.Org X11 libXfont2 runtime librarySecurity Fix(es): libxfont2: Font Server Client encoding[] Out-Of-Bounds Read/Write (CVE-2026-59679) libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client (CVE-2026-44950) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
2 affected components
X.Org libXfont2 runtime library
libxfonts2
Event History
Aug 31, 2026
Advisory Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
RemedyDescriptionAffected Software
Frequently Asked Questions
1
Which package and component names should be checked during asset inventory?
The affected software is identified as the X.Org libXfont2 runtime library and libxfonts2. Inventory searches should include both names.
2
Which issue trackers correspond to the security fixes?
The referenced Red Hat Bugzilla records are 2509620 and 2509622. The fixes address CVE-2026-59679 and CVE-2026-44950.