PT-2026-56334 · X.Org Foundation · Xwayland+1

Published

2026-07-08

·

Updated

2026-07-15

·

CVE-2026-55999

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xorg-server versions prior to 21.2.24 xwayland versions prior to 24.1.13
Description Local attackers with an X connection can cause a heap buffer overflow by providing PCX fonts to the X server. This occurs due to missing glyph boundary checks within the SetFont() function. A heap buffer overflow is a memory corruption issue where a program writes more data to a heap-allocated buffer than it can hold, potentially leading to crashes or arbitrary code execution.
Recommendations Update xorg-server to version 21.2.24 or later. Update xwayland to version 24.1.13 or later.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:38486
ALSA-2026:38487
ALSA-2026:38488
CVE-2026-55999
OPENSUSE-SU-2026:11227-1
OPENSUSE-SU-2026:11244-1
OPENSUSE-SU-2026:21273-1
OPENSUSE-SU-2026:21283-1
SUSE-SU-2026:2786-1
SUSE-SU-2026:2787-1
SUSE-SU-2026:2788-1
SUSE-SU-2026:2789-1
SUSE-SU-2026:2791-1
SUSE-SU-2026:2792-1
ZDI-26-409

Affected Products

Xorg-Server
Xwayland