Fedora Account System
Red Hat Associate
Red Hat Customer
In libXfont2's pcfReadFont() function, the repadded bitmap buffer is allocated using a bitmapSizes[] value read directly from the PCF file without cross-validation against per-glyph metrics. Writing to that array uses the per-glyph metrics from the file also without validation. A malicious PCF font can declare a tiny bitmapSizes[] value (e.g. 16 bytes) for the server's glyph pad index and a per-glyph metrics that exceeds this size, causing a write past the end of the allocation with attacker-controlled content from the PCF BITMAPS payload. No rendering is needed -- the overflow occurs during font parsing itself.
Upstream advisory: https://www.openwall.com/lists/oss-security/2026/07/08/1 Upstream commit: https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bb27b1439968811a3674
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:47079 https://access.redhat.com/errata/RHSA-2026:47079
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:47103 https://access.redhat.com/errata/RHSA-2026:47103
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:47084 https://access.redhat.com/errata/RHSA-2026:47084
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:51061 https://access.redhat.com/errata/RHSA-2026:51061
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:51060 https://access.redhat.com/errata/RHSA-2026:51060
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:51062 https://access.redhat.com/errata/RHSA-2026:51062
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:51058 https://access.redhat.com/errata/RHSA-2026:51058
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:51067 https://access.redhat.com/errata/RHSA-2026:51067
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:51063 https://access.redhat.com/errata/RHSA-2026:51063
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:51059 https://access.redhat.com/errata/RHSA-2026:51059
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:51066 https://access.redhat.com/errata/RHSA-2026:51066