Bug 2496165 (CVE-2026-55999) - CVE-2026-55999 xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow
Summary: CVE-2026-55999 xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow
Keywords:
Status: NEW
Alias: CVE-2026-55999
Deadline: 2026-07-08
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-01 20:21 UTC by OSIDB Bzimport
Modified: 2026-08-11 13:08 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:38486 0 None None None 2026-07-13 09:02:25 UTC
Red Hat Product Errata RHSA-2026:38487 0 None None None 2026-07-13 05:58:08 UTC
Red Hat Product Errata RHSA-2026:38488 0 None None None 2026-07-13 03:55:43 UTC
Red Hat Product Errata RHSA-2026:38489 0 None None None 2026-07-13 04:01:55 UTC
Red Hat Product Errata RHSA-2026:38490 0 None None None 2026-07-13 06:31:58 UTC
Red Hat Product Errata RHSA-2026:49515 0 None None None 2026-08-03 02:57:39 UTC
Red Hat Product Errata RHSA-2026:49516 0 None None None 2026-08-03 03:50:22 UTC
Red Hat Product Errata RHSA-2026:49605 0 None None None 2026-08-03 07:44:38 UTC
Red Hat Product Errata RHSA-2026:49606 0 None None None 2026-08-03 07:59:32 UTC
Red Hat Product Errata RHSA-2026:49608 0 None None None 2026-08-03 08:09:49 UTC
Red Hat Product Errata RHSA-2026:50100 0 None None None 2026-08-04 14:41:19 UTC
Red Hat Product Errata RHSA-2026:50116 0 None None None 2026-08-04 16:24:37 UTC
Red Hat Product Errata RHSA-2026:50117 0 None None None 2026-08-04 17:04:00 UTC
Red Hat Product Errata RHSA-2026:50718 0 None None None 2026-08-05 09:16:56 UTC
Red Hat Product Errata RHSA-2026:52392 0 None None None 2026-08-10 01:55:57 UTC
Red Hat Product Errata RHSA-2026:52397 0 None None None 2026-08-10 01:54:19 UTC
Red Hat Product Errata RHSA-2026:52398 0 None None None 2026-08-10 01:59:37 UTC
Red Hat Product Errata RHSA-2026:53450 0 None None None 2026-08-11 13:08:20 UTC

Description OSIDB Bzimport 2026-07-01 20:21:13 UTC
glamor_font_get() builds a per-font texture atlas by laying out every glyph in the font into a single backing buffer. It computes the slot dimensions from the font's declared maxbounds, but copies each per-glyph bitmap using the individual glyph's metrics (GLYPHHEIGHTPIXELS/GLYPHWIDTHBYTES macros). There is no check that maxbounds actually bounds the per-glyph values.

When the font is loaded from a malicious PCF file whose per-glyph metrics exceed the file's maxbounds, the per-glyph memcpy writes far beyond the heap-allocated slot, producing a heap buffer overflow with attacker-controlled extent and attacker-controlled content.

An authenticated X client can trigger this by using SetFontPath to add a directory containing a crafted PCF font, loading the font with OpenFont, and drawing text on a glamor-backed drawable. Only servers using the glamor acceleration backend (Xorg with modesetting driver, Xwayland) are affected.

Comment 3 errata-xmlrpc 2026-07-13 03:55:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:38488 https://access.redhat.com/errata/RHSA-2026:38488

Comment 4 errata-xmlrpc 2026-07-13 04:01:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:38489 https://access.redhat.com/errata/RHSA-2026:38489

Comment 5 errata-xmlrpc 2026-07-13 05:58:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:38487 https://access.redhat.com/errata/RHSA-2026:38487

Comment 6 errata-xmlrpc 2026-07-13 06:31:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:38490 https://access.redhat.com/errata/RHSA-2026:38490

Comment 7 errata-xmlrpc 2026-07-13 09:02:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:38486 https://access.redhat.com/errata/RHSA-2026:38486

Comment 8 errata-xmlrpc 2026-08-03 02:57:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:49515 https://access.redhat.com/errata/RHSA-2026:49515

Comment 9 errata-xmlrpc 2026-08-03 03:50:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:49516 https://access.redhat.com/errata/RHSA-2026:49516

Comment 10 errata-xmlrpc 2026-08-03 07:44:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:49605 https://access.redhat.com/errata/RHSA-2026:49605

Comment 11 errata-xmlrpc 2026-08-03 07:59:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:49606 https://access.redhat.com/errata/RHSA-2026:49606

Comment 12 errata-xmlrpc 2026-08-03 08:09:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:49608 https://access.redhat.com/errata/RHSA-2026:49608

Comment 13 errata-xmlrpc 2026-08-04 14:41:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:50100 https://access.redhat.com/errata/RHSA-2026:50100

Comment 14 errata-xmlrpc 2026-08-04 16:24:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:50116 https://access.redhat.com/errata/RHSA-2026:50116

Comment 15 errata-xmlrpc 2026-08-04 17:03:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:50117 https://access.redhat.com/errata/RHSA-2026:50117

Comment 16 errata-xmlrpc 2026-08-05 09:16:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:50718 https://access.redhat.com/errata/RHSA-2026:50718

Comment 17 errata-xmlrpc 2026-08-10 01:54:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:52397 https://access.redhat.com/errata/RHSA-2026:52397

Comment 18 errata-xmlrpc 2026-08-10 01:55:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:52392 https://access.redhat.com/errata/RHSA-2026:52392

Comment 19 errata-xmlrpc 2026-08-10 01:59:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:52398 https://access.redhat.com/errata/RHSA-2026:52398

Comment 20 errata-xmlrpc 2026-08-11 13:08:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:53450 https://access.redhat.com/errata/RHSA-2026:53450


Note You need to log in before you can comment on or make changes to this bug.