CVE-2026-56003

Source
https://cve.org/CVERecord?id=CVE-2026-56003
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56003.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-56003
Downstream
Related
Published
2026-07-08T09:25:41.723Z
Modified
2026-07-22T03:52:51.551879Z
Severity
  • 8.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
libXfont2 computeProps Property Buffer Heap Buffer Overflow
Details

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56003.json",
    "cna_assigner": "suse",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "2.0.8"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "fixed": "2.0.8"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "libXfont2"
                },
                {
                    "fixed": "2.0.8"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-122"
    ]
}
References

Affected packages

Git / gitlab.freedesktop.org/xorg/lib/libxfont

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/xorg/lib/libxfont
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

Other
MODULAR_COPY
PRE_xf86-4_3_0_1
XACE-SELINUX-MERGE
XORG-6_7_99_1
XORG-6_7_99_2
XORG-6_7_99_901
XORG-6_7_99_902
XORG-6_7_99_903
XORG-6_7_99_904
XORG-6_8_0
XORG-6_8_1
XORG-6_8_1_901
XORG-6_8_1_902
XORG-6_8_99_1
XORG-6_8_99_10
XORG-6_8_99_11
XORG-6_8_99_12
XORG-6_8_99_13
XORG-6_8_99_14
XORG-6_8_99_15
XORG-6_8_99_16
XORG-6_8_99_2
XORG-6_8_99_3
XORG-6_8_99_4
XORG-6_8_99_5
XORG-6_8_99_6
XORG-6_8_99_7
XORG-6_8_99_8
XORG-6_8_99_9
XORG-6_8_99_900
XORG-6_8_99_901
XORG-6_8_99_902
XORG-6_8_99_903
XORG-6_99_99_900
XORG-6_99_99_901
XORG-6_99_99_902
XORG-6_99_99_903
XORG-6_99_99_904
XORG-7_0
XORG-7_0_99_901
XORG-7_1
XORG-MAIN
lg3d-base
lg3d-rel-0-7-0
libxfont-1_1_0
rel-0-6-1
sco_port_update-base
xf86-012804-2330
xf86-4_3_0_1
xf86-4_3_99_16
xf86-4_3_99_901
xf86-4_3_99_902
xf86-4_3_99_903
xf86-4_3_99_903_special
xf86-4_4_0
xf86-4_4_99_1
libXfont-1.*
libXfont-1.2.0
libXfont-1.2.3
libXfont-1.2.4
libXfont-1.2.5
libXfont-1.2.6
libXfont-1.2.7
libXfont-1.2.8
libXfont-1.2.9
libXfont-1.3.0
libXfont-1.3.1
libXfont-1.3.2
libXfont-1.3.3
libXfont-1.3.4
libXfont-1.4.0
libXfont-1.4.1
libXfont-1.4.2
libXfont-1.4.3
libXfont-1.4.4
libXfont-1.4.5
libXfont-1.4.6
libXfont-1.4.7
libXfont-1.4.99.901
libXfont-1.5.0
libXfont-1.5.1
libXfont2-2.*
libXfont2-2.0.0
libXfont2-2.0.1
libXfont2-2.0.2
libXfont2-2.0.3
libXfont2-2.0.4
libXfont2-2.0.5
libXfont2-2.0.6
libXfont2-2.0.7

Database specific

vanir_signatures
[
    {
        "digest": {
            "length": 1130.0,
            "function_hash": "305693467261253703671747504730923673849"
        },
        "signature_version": "v1",
        "source": "https://gitlab.freedesktop.org/xorg/lib/libxfont@dff957a5158da038a282a59a31fe736702732939",
        "signature_type": "Function",
        "target": {
            "function": "computeProps",
            "file": "src/bitmap/bitscale.c"
        },
        "id": "CVE-2026-56003-67bed1cb",
        "deprecated": false
    },
    {
        "digest": {
            "length": 2439.0,
            "function_hash": "293703442581930006205861720797141146475"
        },
        "signature_version": "v1",
        "source": "https://gitlab.freedesktop.org/xorg/lib/libxfont@dff957a5158da038a282a59a31fe736702732939",
        "signature_type": "Function",
        "target": {
            "function": "ComputeScaledProperties",
            "file": "src/bitmap/bitscale.c"
        },
        "id": "CVE-2026-56003-7f9b2f76",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "281131343815711271337821449936851226192",
                "210311667630768492640958695245772062993",
                "233882945173325561179446775393230888864",
                "114732980097650378417624627542299146139",
                "153239920886179057848356673015263946647",
                "29587648304639848428104921981670008869",
                "86240483338437885627965300440216806198",
                "157885837719112833694540987416506191782",
                "15376256020259753863469953271550533490",
                "8464728880010593466931201364191619395",
                "92281030008611973646715529107869680893",
                "17762819557228494624881022405376328093",
                "219724733597141925306999595708639496601",
                "187943574096112592877582713346026207030",
                "201872628637274241758232591407355583270",
                "263133829981789603571196930190260876324",
                "8439140487531889959835873653087758936",
                "223754830659422146433401547576854611792",
                "313690628631999747361760891436373090384",
                "133827924047915591908502976967123845184",
                "3969747223375102029226908360046799709",
                "22369738808067987139495938707333414149",
                "199796316799321279098808182654727032077",
                "159370811182648703994091583772536173485",
                "229814707275782021391002288666461723052",
                "214563339426754472861133708602303703576",
                "93253685331396806921084062369935223659",
                "230580778599440150011943468232405462917",
                "163505525265826166621098482310967865361",
                "141800620852228603329831116705821511922",
                "20861693569094003682936062617351580629",
                "191637794531106992375623058463016221748",
                "264460795171503881576333328016793312733",
                "81035226483260471105458780523965957408"
            ]
        },
        "signature_version": "v1",
        "source": "https://gitlab.freedesktop.org/xorg/lib/libxfont@dff957a5158da038a282a59a31fe736702732939",
        "signature_type": "Line",
        "target": {
            "file": "src/bitmap/bitscale.c"
        },
        "id": "CVE-2026-56003-eea93c8c",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-22T03:52:51Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56003.json"