CVE-2026-44950 is a heap-based buffer overflow in the libXfont2 font-server client function fs_read_glyphs() in src/fc/fserve.c. The routine copies individual glyph bitmaps into a single destination buffer allocated according to rep->nbytes. It validates each glyph's source position and length against the source bitmap buffer but, before the fix, did not ensure that cumulative destination writes remained within the destination allocation. A malicious font server can submit multiple glyph records with overlapping but individually valid source ranges, causing cumulative attacker-controlled writes beyond the heap buffer.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability tracked as CVE-2026-44950 affecting libXfont2 packages on Oracle Linux 7. The advisory rates impacts to confidentiality, integrity, and availability as high.
A heap buffer overflow in libXfont2's font-server client fs_read_glyphs() function. Per-glyph source-range validation does not enforce bounds on the cumulative destination-buffer cursor, allowing a malicious font server to cause attacker-controlled writes beyond the allocated destination buffer by supplying many glyphs with overlapping valid source ranges.
A critical, remotely exploitable heap buffer overflow in libXfont2's font-server client function fs_read_glyphs(). Insufficient validation of cumulative destination-buffer writes permits a malicious font server to cause an attacker-controlled heap overflow by supplying glyph records with overlapping source offsets.
A heap buffer overflow vulnerability in the libXfont2 Font Server Client that can result in privilege escalation. It affects the libXfont2 package on Red Hat Enterprise Linux 8 systems covered by RHSA-2026:61995.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.