CVE-2026-59679

Public on 2026-08-08
Modified on 2026-08-08
Description
A flaw was found in the libXfont2 font-server client. A remote attacker, by operating a malicious font server, could exploit an out-of-bounds read/write vulnerability. This occurs because the client incorrectly handles font data, leading to an out-of-bounds memory access. This can lead to privilege escalation if the X server runs with root privileges, or a denial of service (crash) if it runs as an unprivileged user.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
8.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core libXfont 2026-08-31 ALAS2-2026-3890 Fixed
Amazon Linux 2 - Core libXfont2 2026-08-31 ALAS2-2026-3889 Fixed
Amazon Linux 2023 libXfont2 2026-08-31 ALAS2023-2026-2112 Fixed
Amazon Linux 2027 Preview libXfont2 Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H