X.Org X11 libXfont2 runtime library
Go to file
RHEL Packaging Agent 7505ca59ac Fix CVE-2026-44950: heap buffer overflow in fs_read_glyphs()
Backport upstream fix for CVE-2026-44950 to libXfont2 2.0.3.
The fix adds a bounds-check for cumulative glyph data writes
in fs_read_glyphs() to prevent heap overflow from overlapping
source offsets sent by a malicious font server. A new regression
test (test-fserve-read-glyphs.c) is included to verify the fix.

CVE: CVE-2026-44950
Upstream patches:
 - c2d222bb22.patch
Resolves: RHEL-222015

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-08-06 10:48:36 +00:00
.gitignore Import rpm: c8s 2023-02-27 13:53:57 -05:00
0001-bitscale-fix-integer-overflow-in-BitmapScaleBitmaps-.patch CVE fix for: 2026-07-08 15:55:17 +02:00
0002-pcfread-validate-bitmap-sizes-and-offsets-against-pe.patch CVE fix for: 2026-07-08 15:55:17 +02:00
0003-bitscale-add-bounds-check-to-computeProps-for-proper.patch CVE fix for: 2026-07-08 15:55:17 +02:00
gating.yaml Bring gating.yaml over from Brew dist-git 2023-03-10 10:59:26 -08:00
libXfont2-2.0.3-CVE-2026-44950.patch Fix CVE-2026-44950: heap buffer overflow in fs_read_glyphs() 2026-08-06 10:48:36 +00:00
libXfont2.spec Fix CVE-2026-44950: heap buffer overflow in fs_read_glyphs() 2026-08-06 10:48:36 +00:00
sources Auto sync2gitlab import of libXfont2-2.0.3-2.el8.src.rpm 2022-05-26 10:10:13 -04:00