ZDI-26-407: X.Org Server PCF Font Parsing Heap-based Buffer Overflow Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56002.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-407?
The severity of ZDI-26-407 is rated at 7.8 based on the CVSS scoring system.
How do I fix ZDI-26-407?
To fix ZDI-26-407, update your X.Org Server to the latest version that addresses this vulnerability.
What type of vulnerability is ZDI-26-407?
ZDI-26-407 is a heap-based buffer overflow vulnerability that allows for privilege escalation.
Who can exploit ZDI-26-407?
Only local attackers who have the ability to execute low-privileged code on the system can exploit ZDI-26-407.
Which software is affected by ZDI-26-407?
ZDI-26-407 affects installations of the X.Org Server.