PatchSiren

X.Org CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH X.Org CVE published 2026-07-08

CVE-2026-56003

CVE-2026-56003 is a heap buffer overflow vulnerability in libXfont2, caused by missing size checking in the property buffer when parsing PCF files in the ComputeScaledProperties() function. This could be exploited by attackers using authenticated X clients to execute code within the X server. The vulnerability has a high impact on systems that use libXfont2, including Linux distributions and X11 environments.

HIGH X.Org CVE published 2026-07-08

CVE-2026-56002

CVE-2026-56002 is a heap buffer overflow vulnerability in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8, allowing authenticated X clients to execute code within the X server. This vulnerability affects systems using libXfont2, particularly those with untrusted clients connecting to X servers. Users should apply patches or updates to mitigate this vulnerability. The issue was [truncated]

HIGH X.Org CVE published 2026-07-08

CVE-2026-56001

CVE-2026-56001 is a heap buffer overflow vulnerability in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32-bit size. This could be used by attackers able to access the X Server to execute code within the X server context. The vulnerability exists in the BitmapScaleBitmaps function of libXfont2, a library used for font rendering in the X Window System. An overflowing 32-bit size can le [truncated]

CRITICAL X.Org CVE published 2026-07-08

CVE-2026-56000

CVE-2026-56000 is a critical vulnerability in xorg-server before 21.2.24 and xwayland before 24.1.13. Local attackers with an X connection can exploit this vulnerability to cause a Heap Use After Free. The vulnerability is due to CommonMakeCurrent() pointing into potentially reallocated memory. The affected products are xorg-server and xwayland, and the vulnerability class is Heap Use After Free. The like [truncated]

HIGH X.Org CVE published 2026-07-08

CVE-2026-55999

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks. This vulnerability has a high CVSS score of 8.5, indicating a high severity. The vulnerability exists in the X server, specifically in the SetFont function. Users of xorg-server before versi [truncated]

CRITICAL X.org CVE published 2017-02-01

CVE-2016-10164

CVE-2016-10164 is a critical libXpm flaw affecting versions before 3.5.12. When a program parses XPM extensions on a 64-bit platform, crafted input can trigger integer overflows in the number of extensions or their combined length, leading to a heap-based buffer overflow. The stated impact includes denial of service and potential arbitrary code execution.