Opened 3 months ago

Closed 2 months ago

#23573 closed enhancement (fixed)

libXfont2-2.0.8 (Xorg library)

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Joe Locash, 3 months ago

Priority: normal → elevated
This release contains the fixes for the issues reported in today's
security advisory:

https://lists.x.org/archives/xorg-announce/2026-July/003714.html

  - CVE-2026-56001: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
  - CVE-2026-56002: PCF Font Parsing Heap Buffer Overflow
  - CVE-2026-56003: computeProps Property Buffer Heap Buffer Overflow

Additionally it contains a number of minor cleanup patches and the
removal of a decades-obsolete compat API.

Adam Jackson (3):
      freetype: Fix encoding string assembly
      freetype: Remove misguided ifdef around BDF charset query
      fontfile: Remove ridiculously old compat API

Alan Coopersmith (2):
      gitlab CI: drop the ci-fairy check-mr job
      gitlab CI: move back to Debian stable image

Peter Hutterer (12):
      pcfread: fix strings memory leak in pcfGetProperties error path
      bdfread: fix copy-paste error in RESOLUTION_X/Y property generation
      bdfread: fix BDF_GENPROPS undercount causing heap buffer overflow
      fsio: fix unchecked realloc
      render: use calloc for FontRec to prevent use of uninitialized memory
      freetype: Remove premature break in find_cmap() Unicode fallback
      bitscale: fix integer overflow in BitmapScaleBitmaps bytestoalloc
      pcfread: validate bitmap sizes and offsets against per-glyph metrics
      bitscale: add bounds check to computeProps for property buffer
      test: fix stubs in font-test-utils for use outside the X server
      test: add PCF security regression tests
      libXfont2 2.0.8

git tag: libXfont2-2.0.8

comment:2 by Joe Locash, 3 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 3 months ago

Milestone: 13.1 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at 15e02087be. Leaving open for SA.

comment:4 by Bruce Dubbs, 2 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-175 has been issued.

Note: See TracTickets for help on using tickets.