OOB Heap Read in libXfont2 query glyphs (CVE-2026-59679)
CVE-2026-59679 Published on September 10, 2026
fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked.
A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.
Vulnerability Analysis
CVE-2026-59679 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Products Associated with CVE-2026-59679
Want to know whenever a new CVE is published for Suse products? stack.watch will email you.
Affected Versions
Container suse/kiosk/tigervnc-x11vnc:1.14-63.8:- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.6-5.el10_2.3 is affected.
- Version ? and below 2.0.6-5.el10_2.3 is affected.
- Version ? and below 2.0.3-2.el8_10.3 is affected.
- Version ? and below 2.0.3-2.el8_10.3 is affected.
- Version ? and below 2.0.3-12.el9_8.3 is affected.
- Version ? and below 2.0.3-12.el9_8.3 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.3-3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.3-150000.3.6.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-160000.5.1 is affected.
- Version ? and below 2.0.7-3.1 is affected.
- Version ? and below 2.0.7-3.1 is affected.
- Version ? and below 2.0.7-3.1 is affected.
- Version ? and below 2.0.7-3.1 is affected.
- Version ?, <= 2.0.8 is affected.