X.Org released security updates for X.Org Server 21.1.24, Xwayland 24.1.13, and libXfont2 2.0.8 to address five vulnerabilities tied largely to malformed PCF fonts and unsafe graphics context handling. The X server and Xwayland fixes cover CVE-2026-55999, a heap buffer overflow in glamor font atlas handling that an authenticated X client can trigger with a crafted PCF font on glamor-backed servers, and CVE-2026-56000, a use-after-free in CommonMakeCurrent() involving GLX contextTags that can be reached through malicious GLX context creation and MakeCurrent requests.
The libXfont2 update fixes CVE-2026-56001, an integer-overflow-driven heap buffer overflow in BitmapScaleBitmaps(); CVE-2026-56002, a heap buffer overflow in pcfReadFont() during PCF parsing; and CVE-2026-56003, a heap buffer overflow in ComputeScaledProperties() caused by an unchecked fixed-size property buffer. X.Org said the flaws were reported anonymously through Trend Micro's Zero Day Initiative, and downstream reporting warned the bugs could enable privilege escalation or potentially remote code execution where the X server runs as root or where X11 forwarding is exposed over SSH.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
X.Org disclosed CVE-2026-56001, CVE-2026-56002, and CVE-2026-56003 in libXfont2 versions prior to 2.0.8 and released fixes in libXfont2-2.0.8. The vulnerabilities involve malformed PCF font handling and were found by an anonymous researcher working with Trend Micro Zero Day Initiative.
X.Org disclosed CVE-2026-55999 and CVE-2026-56000 affecting X.Org X server before 21.1.24 and Xwayland before 24.1.13. The issues were fixed in xorg-server-21.1.24 and xwayland-24.1.13, and the vulnerabilities were reported anonymously through Trend Micro Zero Day Initiative.
X.Org committed a security fix in xserver's glamor font rendering code for CVE-2026-55999, rejecting malformed PCF fonts whose per-glyph metrics are negative or exceed maxbounds-derived atlas slot sizes and falling back to software rendering. The commit also added tests and a minimal malicious PCF builder to verify crafted fonts no longer crash the server.
X.Org published a security advisory covering multiple security issues affecting X.Org X server and Xwayland. This advisory predates the later July 2026 public disclosure and release entries already in the timeline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
16 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegitlab.freedesktop.org
Open sourcegitlab.freedesktop.org
Open sourcegitlab.freedesktop.org
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.