USN-8560-1: libXfont vulnerabilities

Publication date

20 July 2026

Overview

Several security issues were fixed in libXfont.


Packages

  • libxfont - X11 font rasterisation library

Details

It was discovered that libXfont incorrectly handled scaling bitmap
fonts, leading to a heap buffer overflow. An attacker able to access
the X server could use this issue to cause libXfont to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2026-56001)

It was discovered that libXfont did not properly check glyph bounds
when reading PCF fonts, leading to a heap buffer overflow. An
authenticated X client could use this issue to cause libXfont to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2026-56002)

It was discovered that libXfont did not properly check the size of the
property buffer when parsing PCF fonts, leading to a heap buffer
overflow. An authenticated X client could use this issue to cause
libXfont to crash, resulting in a denial of service, or possibly
execute...

It was discovered that libXfont incorrectly handled scaling bitmap
fonts, leading to a heap buffer overflow. An attacker able to access
the X server could use this issue to cause libXfont to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2026-56001)

It was discovered that libXfont did not properly check glyph bounds
when reading PCF fonts, leading to a heap buffer overflow. An
authenticated X client could use this issue to cause libXfont to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2026-56002)

It was discovered that libXfont did not properly check the size of the
property buffer when parsing PCF fonts, leading to a heap buffer
overflow. An authenticated X client could use this issue to cause
libXfont to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-56003)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute libxfont2 –  1:2.0.6-2ubuntu0.2
24.04 LTS noble libxfont2 –  1:2.0.6-1+deb13u1build0.24.04.2
22.04 LTS jammy libxfont2 –  1:2.0.5-1ubuntu0.2
20.04 LTS focal libxfont2 –  1:2.0.3-1ubuntu0.20.04.1~esm2  
18.04 LTS bionic libxfont2 –  1:2.0.3-1ubuntu0.1~esm2  
16.04 LTS xenial libxfont1 –  1:1.5.1-1ubuntu0.16.04.4+esm2  
14.04 LTS trusty libxfont1 –  1:1.4.7-1ubuntu0.4+esm2  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›