Opened 2 months ago
Closed 2 months ago
#23697 closed enhancement (fixed)
libXfont2-2.0.9 (Xorg library)
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (4)
comment:1 by , 2 months ago
| Priority: | normal → elevated |
|---|---|
| Severity: | normal → medium |
comment:2 by , 2 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 2 months ago
| Milestone: | 13.1 → 98-Security |
|---|---|
| Owner: | changed from to |
| Status: | assigned → new |
Fixed at 9db58a1869. Leaving open for SA.
comment:4 by , 2 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-192 has been issued.
Note:
See TracTickets
for help on using tickets.

libXfont2 2.0.9 is now available This release contains the fixes for the issues reported in today's security advisory: https://lists.x.org/archives/xorg-announce/2026-August/003734.html - CVE-2026-59679: Font Server Client encoding Out-Of-Bounds Read/Write - CVE-2026-44950: Font Server Client Cumulative Glyph Data Heap Buffer Overflow Additionally, it changes a build-time default. Previously fontserver support was compiled in by default unless --disable-fc was provided at configure time. The new default is *disabled by default* unless --enable-fc is provided at configure time. Doing so protects us from future fontserver-connection related issues. Fontservers have been deprecated for many years and the vast majority of users will not notice this changed default (Debian has built with --disable-fc for years). Peter Hutterer (5): README: fix documentation for --enable-snfformat Disable fontserver support by default fserve: validate num_chars against encoding array size in fs_read_glyphs fserve: bounds-check cumulative glyph data writes in fs_read_glyphs libXfont2 2.0.9 git tag: libXfont2-2.0.9