← Back to CVE search

CVE-2026-55999

xorg-server

Description

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

CVSS 8.5EPSS 0.269%Risk 0.87
View source
Published
2026-07-08 09:16:29
Affected versions
<21.2.24
Type
Operating system
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H