- Description
- Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
- Source
- meissner@suse.de
- NVD status
- Analyzed
- Products
- x_server, xwayland
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- meissner@suse.de
- CWE-122
- Hype score
- Not currently trending
We released the #XLibre Xserver 25.0.0.25, 25.1.9, and beta 25.2.2 during the last 4 days containing #security fixes for #CVE-2026-55999 and CVE-2026-56000. We recommend everyone update ASAP. https://t.co/NyxJgr94nL https://t.co/8hnK1KAfdb https://t.co/Sci14c5fiI
@XLibreDev
27 Jul 2026
1309 Impressions
18 Retweets
100 Likes
1 Bookmark
0 Replies
0 Quotes
🚨*CVE* CVE-2026-55999 Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overf… https://t.co/PsKHKy5O9C ----- Traducción: CVE-2026-55999 Ata… https://t.co/utmtNg
@infoflowcloud
8 Jul 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7952D780-B208-4D17-BD47-59B9C820E66F",
"versionEndExcluding": "21.2.24",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:x.org:xwayland:*:*:*:*:*:*:*:*",
"matchCriteriaId": "17B539FB-255A-427D-9DD3-659AC3BEE4D4",
"versionEndExcluding": "24.1.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]