Opened 2 months ago

Closed 2 months ago

#23697 closed enhancement (fixed)

libXfont2-2.0.9 (Xorg library)

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Joe Locash, 2 months ago

Priority: normal → elevated
Severity: normal → medium
libXfont2 2.0.9 is now available

This release contains the fixes for the issues reported in today's security advisory:
https://lists.x.org/archives/xorg-announce/2026-August/003734.html

- CVE-2026-59679: Font Server Client encoding Out-Of-Bounds Read/Write
- CVE-2026-44950: Font Server Client Cumulative Glyph Data Heap Buffer Overflow

Additionally, it changes a build-time default. Previously fontserver support
was compiled in by default unless --disable-fc was provided at configure time.
The new default is *disabled by default* unless --enable-fc is provided at
configure time. Doing so protects us from future fontserver-connection related
issues. Fontservers have been deprecated for many years and the vast majority
of users will not notice this changed default (Debian has built with
--disable-fc for years).

Peter Hutterer (5):
      README: fix documentation for --enable-snfformat
      Disable fontserver support by default
      fserve: validate num_chars against encoding array size in fs_read_glyphs
      fserve: bounds-check cumulative glyph data writes in fs_read_glyphs
      libXfont2 2.0.9

git tag: libXfont2-2.0.9

comment:2 by Joe Locash, 2 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 2 months ago

Milestone: 13.1 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at 9db58a1869. Leaving open for SA.

comment:4 by Bruce Dubbs, 2 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-192 has been issued.

Note: See TracTickets for help on using tickets.