CVE-2026-44950

high
Published 2026-08-17 · Modified 2026-08-18
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
8.0

Description

Important: libXfont2 security update

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client Red Hat statement This is an Important flaw. A heap buffer overflow in the `libXfont2` font server client can be triggered by a malicious font server. If the X server runs as root, this could lead to privilege escalation; otherwise, it results in a denial of service. Red Hat Enterprise Linux…

Description

libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client

Red Hat statement

This is an Important flaw. A heap buffer overflow in the `libXfont2` font server client can be triggered by a malicious font server. If the X server runs as root, this could lead to privilege escalation; otherwise, it results in a denial of service. Red Hat Enterprise Linux typically runs the X server as an unprivileged user, mitigating the privilege escalation risk but still allowing for denial of service.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10libXfont2-0:2.0.6-5.el10_2.3RHSA-2026:554482026-08-17T00:00:00Z
Red Hat Enterprise Linux 8libXfont2-0:2.0.3-2.el8_10.3RHSA-2026:554462026-08-17T00:00:00Z
Red Hat Enterprise Linux 9libXfont2-0:2.0.3-12.el9_8.3RHSA-2026:554472026-08-17T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 7libXfont2Affected

Apply commands

bash fix
Apply RHSA-2026:55448 for Red Hat Enterprise Linux 10
yum update -y libXfont2
# or:
dnf upgrade -y libXfont2

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 7Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
Affected
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected
sid Fixed 1:2.0.9-1
forky Fixed 1:2.0.9-1
bullseye Affected
bookworm Affected
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
8 Fixed libXfont2-devel-2.0.3-2.el8_10.3.i686.rpm

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.