X.Org released libXfont2 2.0.9 to fix two memory-corruption flaws in the font-server client: CVE-2026-59679, an out-of-bounds heap read/write caused by inconsistent character and extent counts in font-server replies, and CVE-2026-44950, a heap-buffer overflow in fs_read_glyphs() caused by cumulative glyph bitmap writes exceeding the allocated buffer. A malicious font server can exploit either vulnerability to crash an unprivileged X server or potentially gain elevated privileges where the X server runs as root; both issues are incomplete fixes for CVE-2014-0210.
Red Hat has issued Important security updates for affected RHEL 10 and RHEL 9 SAP-related Update Services and lifecycle channels. Fixed packages include libXfont2 2.0.6-5.el10_2.3 for RHEL 10, 2.0.3-12.el9_4.3 for RHEL 9.4 channels, and 2.0.3-12.el9_2.3 for RHEL 9.2 channels, covering supported x86_64, aarch64, ppc64le, s390x, and, where applicable, i686 systems. Organizations should apply the relevant vendor updates, particularly on systems operating X servers with root privileges.

Get the actors, campaigns, and ATT&CK mapping behind it.
17 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important advisory RHSA-2026:61995 for affected RHEL 8 and RHEL AUS 8.4 systems, remediating CVE-2026-59679 and CVE-2026-44950 in libXfont2. The advisory recommends updating the affected package and lists no known exploits.
Amazon Linux published advisory ALAS2-2026-3889 for Amazon Linux 2, updating libXfont2 to address CVE-2026-44950 and CVE-2026-59679. Systems with libXfont2 versions earlier than 2.0.3-1 were affected; the advisory recommended updating with yum and reported no known exploits.
Amazon published advisory ALAS2-2026-3890 for Amazon Linux 2, updating libXfont to address CVE-2026-44950 and CVE-2026-59679. Systems running versions earlier than 1.5.4-1 were affected; no known exploits were available at the time of the advisory.
Red Hat published Important advisory RHSA-2026:61756 for affected RHEL 8.8 E4S and TUS configurations, remediating CVE-2026-59679 and CVE-2026-44950 in libXfont2. The advisory recommends updating the affected libXfont2 package; no known exploits were reported.
Red Hat published Important advisory RHSA-2026:61390 for affected RHEL 9.6 EUS libXfont2 and libXfont2-devel packages, remediating CVE-2026-59679 and CVE-2026-44950. The advisory recommends updating libXfont2; the associated Nessus check reported no known public exploits.
Amazon Linux 2023 published advisory ALAS2023-2026-2112 to remediate CVE-2026-44950 and CVE-2026-59679 in libXfont2 and libXfont2-devel. The update was made available through Amazon Linux release version 2023.12.20260831.
Red Hat published Important advisory RHSA-2026:61755 for affected RHEL 8 and RHEL AUS 8.6 systems, remediating CVE-2026-59679 and CVE-2026-44950 in libXfont2. The advisory recommended updating the installed libXfont2 package; no known exploits were reported.
Alibaba Cloud Linux 3 published security advisory ALSA-2026-0269 to address CVE-2026-44950 and CVE-2026-59679 in libxfont2, libxfont2-devel, and libxfont2-doc packages. The advisory reported no known exploits.
Red Hat issued Important advisory RHSA-2026:59312 for RHEL 9.4 Update Services for SAP Solutions, AUS, and Extended Life Cycle offerings. The update provided libXfont2 2.0.3-12.el9_4.3 packages to address CVE-2026-59679 and CVE-2026-44950.
Red Hat issued Important advisory RHSA-2026:59311 for RHEL 9.2 Update Services for SAP Solutions and associated lifecycle channels. It delivered libXfont2 2.0.3-12.el9_2.3 to fix CVE-2026-59679 and CVE-2026-44950.
TencentOS Server 3 published advisory TSSA-2026:0901 and a patch addressing CVE-2026-44950 and CVE-2026-59679 in libXfont2. The advisory stated that no known exploits were available.
Red Hat issued Important advisory RHSA-2026:55447 for Red Hat Enterprise Linux 9, remediating CVE-2026-59679 and CVE-2026-44950. The advisory provides fixed libXfont2 2.0.3-12.el9_8.3 packages for supported architectures and applicable RHEL 9 lifecycle, SAP, and CodeReady Linux Builder repositories.
Red Hat issued Important advisory RHSA-2026:55446 for RHEL 8 and RHEL 8.10 Extended Life Cycle deployments, remediating CVE-2026-59679 and CVE-2026-44950. The advisory provides libXfont2 2.0.3-2.el8_10.3 packages, with related CodeReady Linux Builder packages.
Red Hat published RHSA-2026:55448, rated Important, to remediate CVE-2026-59679 and CVE-2026-44950 in Red Hat Enterprise Linux 10. The advisory supplied fixed libXfont2 version 2.0.6-5.el10_2.3 packages for supported architectures.
X.Org disclosed CVE-2026-59679 and CVE-2026-44950, two memory-corruption flaws in the libXfont2 font-server client that were incomplete fixes for CVE-2014-0210. The libXfont2 2.0.9 release remediated both issues; exploitation may enable privilege escalation for root-run X servers or denial of service for unprivileged servers.
An upstream libXfont commit added cumulative destination-buffer bounds checks in fs_read_glyphs() to prevent a malicious font server from causing writes beyond the allbits allocation through overlapping glyph ranges. The change returns AllocError on overflow and adds regression tests for malformed overlapping glyph data and valid non-overlapping replies.
An upstream libXfont commit added validation in fs_read_glyphs() to reject FS_QueryXBitmaps16 replies whose num_chars exceeds the allocated encoding[] size, preventing out-of-bounds reads and writes caused by a malicious font server. The change also validates the glyph index and adds regression tests for malformed oversized and valid replies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
21 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceexplore.alas.aws.amazon.com
Open sourceopenwall.com
Open sourcegitlab.freedesktop.org
Open sourcegitlab.freedesktop.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.