OOB Heap Read in libXfont2 query glyphs (CVE-2026-59679)
CVE-2026-59679 Published on September 10, 2026

fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.

NVD

Vulnerability Analysis

CVE-2026-59679 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Products Associated with CVE-2026-59679

Want to know whenever a new CVE is published for Suse products? stack.watch will email you.

 
 
 
 

Affected Versions

Container suse/kiosk/tigervnc-x11vnc:1.14-63.8: Container suse/kiosk/xorg:21.1-83.7: SUSE Image SLES15-SP6-SAP: SUSE Image SLES15-SP6-SAP-Azure: SUSE Image SLES15-SP6-SAP-Azure-3P: SUSE Image SLES15-SP6-SAP-BYOS: SUSE Image SLES15-SP6-SAP-BYOS-Azure: SUSE Image SLES15-SP6-SAP-BYOS-EC2: SUSE Image SLES15-SP6-SAP-BYOS-GCE: SUSE Image SLES15-SP6-SAP-EC2: SUSE Image SLES15-SP6-SAP-GCE: SUSE Image SLES15-SP6-SAP-Hardened: SUSE Image SLES15-SP6-SAP-Hardened-Azure: SUSE Image SLES15-SP6-SAP-Hardened-BYOS: SUSE Image SLES15-SP6-SAP-Hardened-BYOS-Azure: SUSE Image SLES15-SP6-SAP-Hardened-BYOS-EC2: SUSE Image SLES15-SP6-SAP-Hardened-BYOS-GCE: SUSE Image SLES15-SP6-SAP-Hardened-EC2: SUSE Image SLES15-SP6-SAP-Hardened-GCE: SUSE Image SLES15-SP6-SAPCAL: SUSE Image SLES15-SP6-SAPCAL-Azure: SUSE Image SLES15-SP6-SAPCAL-EC2: SUSE Image SLES15-SP6-SAPCAL-GCE: SUSE Image SLES15-SP7-SAP-Azure: SUSE Image SLES15-SP7-SAP-Azure-3P: SUSE Image SLES15-SP7-SAP-BYOS-Azure: SUSE Image SLES15-SP7-SAP-BYOS-EC2: SUSE Image SLES15-SP7-SAP-BYOS-GCE: SUSE Image SLES15-SP7-SAP-EC2: SUSE Image SLES15-SP7-SAP-GCE: SUSE Image SLES15-SP7-SAP-GCE-3P: SUSE Image SLES15-SP7-SAP-Hardened-Azure: SUSE Image SLES15-SP7-SAP-Hardened-BYOS-Azure: SUSE Image SLES15-SP7-SAP-Hardened-BYOS-EC2: SUSE Image SLES15-SP7-SAP-Hardened-BYOS-GCE: SUSE Image SLES15-SP7-SAP-Hardened-GCE: SUSE Image SLES15-SP7-SAPCAL-Azure: SUSE Image SLES15-SP7-SAPCAL-EC2: SUSE Image SLES15-SP7-SAPCAL-GCE: SUSE Image SLES-SAP-Azure: SUSE Image SLES-SAP-Azure-3P: SUSE Image SLES-SAP-BYOS-Azure: SUSE Image SLES-SAP-BYOS-EC2: SUSE Image SLES-SAP-BYOS-GCE: SUSE Image SLES-SAP-GCE: SUSE Image SLES-SAP-GCE-3P: SUSE Image SLES-SAPCAL-GCE: SUSE Image SLES12-SP5-Azure-SAP-BYOS: SUSE Image SLES12-SP5-Azure-SAP-On-Demand: SUSE Image SLES12-SP5-EC2-SAP-BYOS: SUSE Image SLES12-SP5-EC2-SAP-On-Demand: SUSE Image SLES12-SP5-GCE-SAP-BYOS: SUSE Image SLES12-SP5-GCE-SAP-On-Demand: SUSE Liberty Linux 10: SUSE Liberty Linux 10: SUSE Liberty Linux 8: SUSE Liberty Linux 8: SUSE Liberty Linux 9: SUSE Liberty Linux 9: SUSE Linux Enterprise Desktop 15 SP7: SUSE Linux Enterprise Desktop 15 SP7: SUSE Linux Enterprise Module for Basesystem 15 SP7: SUSE Linux Enterprise Module for Basesystem 15 SP7: SUSE Linux Enterprise Server 15 SP7: SUSE Linux Enterprise Server 15 SP7: SUSE Linux Enterprise Server for SAP Applications 15 SP7: SUSE Linux Enterprise Server for SAP Applications 15 SP7: SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS: SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS: SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS: SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS: SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS: SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS: SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS: SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS: SUSE Linux Enterprise Server 12 SP5-LTSS: SUSE Linux Enterprise Server 15 SP4-LTSS: SUSE Linux Enterprise Server 15 SP4-LTSS: SUSE Linux Enterprise Server 15 SP5-LTSS: SUSE Linux Enterprise Server 15 SP5-LTSS: SUSE Linux Enterprise Server 15 SP6-LTSS: SUSE Linux Enterprise Server 15 SP6-LTSS: SUSE Linux Enterprise Server 16.0: SUSE Linux Enterprise Server 16.0: SUSE Linux Enterprise Server for SAP applications 16.0: SUSE Linux Enterprise Server for SAP applications 16.0: SUSE Linux Enterprise Server LTSS Extended Security 12 SP5: SUSE Linux Enterprise Server for SAP Applications 15 SP4: SUSE Linux Enterprise Server for SAP Applications 15 SP4: SUSE Linux Enterprise Server for SAP Applications 15 SP5: SUSE Linux Enterprise Server for SAP Applications 15 SP5: SUSE Linux Enterprise Server for SAP Applications 15 SP6: SUSE Linux Enterprise Server for SAP Applications 15 SP6: SUSE Manager Proxy LTS 4.3: SUSE Manager Proxy LTS 4.3: SUSE Manager Retail Branch Server LTS 4.3: SUSE Manager Retail Branch Server LTS 4.3: SUSE Manager Server LTS 4.3: SUSE Manager Server LTS 4.3: openSUSE Leap 16.0: openSUSE Leap 16.0: openSUSE Tumbleweed: openSUSE Tumbleweed: openSUSE Tumbleweed: openSUSE Tumbleweed: libXfont2: