Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in libXfont.. ========================================================================== Ubuntu Security Notice USN-8560-1 July 20, 2026 libxfont vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in libXfont. Software Description: - libxfont: X11 font rasterisation library Details: It was discovered that libXfont incorrectly handled scaling bitmap fonts, leading to a heap buffer overflow. An attacker able to access the X server could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-56001) It was discovered that libXfont did not properly check glyph bounds when reading PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-56002) It was discovered that libXfont did not properly check the size of the property buffer when parsing PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-56003) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libxfont2 1:2.0.6-2ubuntu0.2 Ubuntu 24.04 LTS libxfont2 1:2.0.6-1+deb13u1build0.24.04.2 Ubuntu 22.04 LTS libxfont2 1:2.0.5-1ubuntu0.2 Ubuntu 20.04 LTS libxfont2 1:2.0.3-1ubuntu0.20.04.1~esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS libxfont2 1:2.0.3-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS libxfont1 1:1.5.1-1ubuntu0.16.04.4+esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS libxfont1 1:1.4.7-1ubuntu0.4+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8560-1 CVE-2017-16611, CVE-2026-56001, CVE-2026-56002, CVE-2026-56003 Package Information: https://launchpad.net/ubuntu/+source/libxfont/1:2.0.6-2ubuntu0.2 https://launchpad.net/ubuntu/+source/libxfont/1:2.0.6-1+deb13u1build0.24.04.2 https://launchpad.net/ubuntu/+source/libxfont/1:2.0.5-1ubuntu0.2 . Explore the critical updates for libXfont addressing denial of service issues and buffer overflows impacting various Ubuntu versions.. libXfont update, Ubuntu security patches, heap overflow fixes. . Severity: Important. LinuxSecurity.com Team
Several vulnerabilities were discovered in libXfont, the X11 font rasterisation library, which may result in arbitrary code execution in the X server context for authenticated X clients. For the stable distribution (trixie), these problems have been fixed in version 1:2.0.6-1+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6388-1
A series of heap overflows in bitmap/PCF parser code could be used by authenticated attackers to execute code in the X server context. CVE-2026-56001 A heap buffer overflow in BitmapScaleBitmaps in due to an overflowing 32-bit size.. Debian LTS Advisory DLA-4678-1
n issue has been found in libxfont, an X11 font rasterisation library. By creating symlinks, a local attacker can open (but not read) local files as user root. This might create unwanted actions with special files like . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2901-1
Security fix for CVE-2017-13720 and CVE-2017-13722. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-2783ef2c63 2017-10-25 21:34:15.278005 --------------------------------------------------------------------------------Name : libXfont Product : Fedora 26 Version : 1.5.2 Release : 5.fc26 URL : https://www.x.org/wiki/ Summary : X.Org X11 libXfont runtime library Description : X.Org X11 libXfont runtime library --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-13720 and CVE-2017-13722 --------------------------------------------------------------------------------References: [ 1 ] Bug #1500693 - CVE-2017-13722 libXfont: Insufficient input validation in pcfread.c https://bugzilla.redhat.com/show_bug.cgi?id=1500693 [ 2 ] Bug #1500690 - CVE-2017-13720 libXfont: Insufficient input validation in fontdir.c https://bugzilla.redhat.com/show_bug.cgi?id=1500690 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libXfont' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Two vulnerabilities were found in libXfont, the X11 font rasterisation library, which could result in denial of service or memory disclosure. For the oldstable distribution (jessie), these problems have been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3995-1
It was discovered that there two vulnerabilities the library providing font selection and rasterisation, libxfont: * CVE-2017-13720: If a pattern contained a '?' character any character . Hash: SHA256 Package : libxfont Version : 1:1.4.5-5+deb7u1 CVE IDs : CVE-2017-13720 CVE-2017-13722 It was discovered that there two vulnerabilities the library providing font selection and rasterisation, libxfont: * CVE-2017-13720: If a pattern contained a '?' character any character in the string is skipped even if it was a '\0'. The rest of the matching then read invalid memory. * CVE-2017-13722: A malformed PCF file could cause the library to make reads from random heap memory that was behind the `strings` buffer, leading to an application crash or a information leak. For Debian 7 "Wheezy", this issue has been fixed in libxfont version 1:1.4.5-5+deb7u1. We recommend that you upgrade your libxfont packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
libXfont could be made to crash or run programs as an administrator if it opened a specially crafted bdf font file.. =========================================================================Ubuntu Security Notice USN-2536-1 March 18, 2015 libxfont vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: libXfont could be made to crash or run programs as an administrator if it opened a specially crafted bdf font file. Software Description: - libxfont: X11 font rasterisation library Details: Ilja van Sprundel, Alan Coopersmith, and William Robinet discovered that libXfont incorrectly handled malformed bdf fonts. A local attacker could use this issue to cause libXfont to crash, or possibly execute arbitrary code in order to gain privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: libxfont1 1:1.4.99.901-1ubuntu0.1 Ubuntu 14.04 LTS: libxfont1 1:1.4.7-1ubuntu0.2 Ubuntu 12.04 LTS: libxfont1 1:1.4.4-1ubuntu0.3 Ubuntu 10.04 LTS: libxfont1 1:1.4.1-1ubuntu0.4 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2536-1 CVE-2015-1802, CVE-2015-1803, CVE-2015-1804 Package Information: https://launchpad.net/ubuntu/+source/libxfont/1:1.4.99.901-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libxfont/1:1.4.7-1ubuntu0.2 https://launchpad.net/ubuntu/+source/libxfont/1:1.4.4-1ubuntu0.3 https://launchpad.net/ubuntu/+source/libxfont/1:1.4.1-1ubuntu0.4 . Enhance your Ubuntu installations to address libXfont security flaws that might result in system instability or illicit code execution..libxfont, ubuntu vulnerabilities, exploit fix, code execution. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.