CVE-2026-55999 Details
Description
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
A heap buffer overflow vulnerability has been identified in X.Org Server versions prior to 21.1.24 and Xwayland versions prior to 24.1.13. This vulnerability allows local attackers with an X connection to provide malicious PCF fonts to the X server, leading to potential memory corruption. The issue arises in the glamor acceleration backend, which is used by default in Xwayland and can be enabled in X.Org Server with the modesetting driver.
Users can upgrade to X.Org Server 21.1.24 or Xwayland 24.1.13 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.freedesktop.org/xorg/xserver/-/commit/fbf7bac22e2c6bd627fb042742a23318263edae1 | [email protected] | Patch |
| https://www.openwall.com/lists/oss-security/2026/07/08/2 | [email protected] | Mailing ListPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| x.org x server | < 21.2.24 |
CPE
Remediation
| |
| x.org xwayland | < 24.1.13 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |