Heap buffer overflow in libXfont2 fs_read_glyphs()
CVE-2026-44950 Published on September 10, 2026
fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation.
A malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content.
Vulnerability Analysis
CVE-2026-44950 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Products Associated with CVE-2026-44950
Want to know whenever a new CVE is published for Suse products? stack.watch will email you.
Affected Versions
Container suse/kiosk/tigervnc-x11vnc:1.14-63.8:- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.6-5.el10_2.3 is affected.
- Version ? and below 2.0.6-5.el10_2.3 is affected.
- Version ? and below 2.0.3-2.el8_10.3 is affected.
- Version ? and below 2.0.3-2.el8_10.3 is affected.
- Version ? and below 2.0.3-12.el9_8.3 is affected.
- Version ? and below 2.0.3-12.el9_8.3 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-3.1 is affected.
- Version ? and below 2.0.7-3.1 is affected.
- Version ? and below 2.0.7-3.1 is affected.
- Version ? and below 2.0.7-3.1 is affected.
- Version ?, <= 2.0.8 is affected.