yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2026-55999
Component Overview
Vulnerability Overview
Name
CVE-2026-55999
Source
NVD (
link
)
Debian (
link
)
Description
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
CWEs
CWE-122
Published Date
Jul 8, 2026
Updated Date
Jul 9, 2026
Workaround
-
Advisories
https://gitlab.freedesktop.org/xorg/xserver/-/commit/fbf7bac22e2c6bd627fb042742a23318263edae1
Patch
https://www.openwall.com/lists/oss-security/2026/07/08/2
Mailing List
Analysis
#
Affected Component
Analysis
xwayland
Exploitable
Vulnerability Ratings
#
8.5
CVSSv31
7.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
xwayland
buildroot
2025.02.x
24.1.13
Not Affected
xwayland
buildroot
master
24.1.13
Not Affected
xwayland
yocto
kirkstone
22.1.8
Exploitable
xwayland
yocto
master
24.1.13
Not Affected