A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56003.json",
"cna_assigner": "suse",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"fixed": "2.0.8"
}
]
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "2.0.8"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "libXfont2"
},
{
"fixed": "2.0.8"
}
]
}
],
"cwe_ids": [
"CWE-122"
]
}[
{
"digest": {
"length": 1130.0,
"function_hash": "305693467261253703671747504730923673849"
},
"signature_version": "v1",
"source": "https://gitlab.freedesktop.org/xorg/lib/libxfont@dff957a5158da038a282a59a31fe736702732939",
"signature_type": "Function",
"target": {
"function": "computeProps",
"file": "src/bitmap/bitscale.c"
},
"id": "CVE-2026-56003-67bed1cb",
"deprecated": false
},
{
"digest": {
"length": 2439.0,
"function_hash": "293703442581930006205861720797141146475"
},
"signature_version": "v1",
"source": "https://gitlab.freedesktop.org/xorg/lib/libxfont@dff957a5158da038a282a59a31fe736702732939",
"signature_type": "Function",
"target": {
"function": "ComputeScaledProperties",
"file": "src/bitmap/bitscale.c"
},
"id": "CVE-2026-56003-7f9b2f76",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"281131343815711271337821449936851226192",
"210311667630768492640958695245772062993",
"233882945173325561179446775393230888864",
"114732980097650378417624627542299146139",
"153239920886179057848356673015263946647",
"29587648304639848428104921981670008869",
"86240483338437885627965300440216806198",
"157885837719112833694540987416506191782",
"15376256020259753863469953271550533490",
"8464728880010593466931201364191619395",
"92281030008611973646715529107869680893",
"17762819557228494624881022405376328093",
"219724733597141925306999595708639496601",
"187943574096112592877582713346026207030",
"201872628637274241758232591407355583270",
"263133829981789603571196930190260876324",
"8439140487531889959835873653087758936",
"223754830659422146433401547576854611792",
"313690628631999747361760891436373090384",
"133827924047915591908502976967123845184",
"3969747223375102029226908360046799709",
"22369738808067987139495938707333414149",
"199796316799321279098808182654727032077",
"159370811182648703994091583772536173485",
"229814707275782021391002288666461723052",
"214563339426754472861133708602303703576",
"93253685331396806921084062369935223659",
"230580778599440150011943468232405462917",
"163505525265826166621098482310967865361",
"141800620852228603329831116705821511922",
"20861693569094003682936062617351580629",
"191637794531106992375623058463016221748",
"264460795171503881576333328016793312733",
"81035226483260471105458780523965957408"
]
},
"signature_version": "v1",
"source": "https://gitlab.freedesktop.org/xorg/lib/libxfont@dff957a5158da038a282a59a31fe736702732939",
"signature_type": "Line",
"target": {
"file": "src/bitmap/bitscale.c"
},
"id": "CVE-2026-56003-eea93c8c",
"deprecated": false
}
]
"2026-07-22T03:52:51Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56003.json"