yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2026-56001
Component Overview
Vulnerability Overview
Name
CVE-2026-56001
Source
NVD (
link
)
Debian (
link
)
Description
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont
CWEs
CWE-122
Published Date
Jul 8, 2026
Updated Date
Jul 9, 2026
Workaround
-
Advisories
https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778
Patch
https://www.openwall.com/lists/oss-security/2026/07/08/1
Mailing List
Analysis
#
Affected Component
Analysis
libxfont2
Exploitable
Vulnerability Ratings
#
8.5
CVSSv31
8.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
xlib_libXfont2
buildroot
2025.02.x
2.0.8
Not Affected
xlib_libXfont2
buildroot
master
2.0.8
Not Affected
libxfont2
yocto
master
2.0.8
Not Affected
libxfont
yocto
scarthgap
1.5.4
Not Affected
libxfont2
yocto
scarthgap
2.0.6
Exploitable