Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 12 articles for you...
172

Ubuntu libXfont Important Denial Of Service Heap Overflow Vuln 8560-1

Several security issues were fixed in libXfont.. ========================================================================== Ubuntu Security Notice USN-8560-1 July 20, 2026 libxfont vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in libXfont. Software Description: - libxfont: X11 font rasterisation library Details: It was discovered that libXfont incorrectly handled scaling bitmap fonts, leading to a heap buffer overflow. An attacker able to access the X server could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-56001) It was discovered that libXfont did not properly check glyph bounds when reading PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-56002) It was discovered that libXfont did not properly check the size of the property buffer when parsing PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-56003) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libxfont2 1:2.0.6-2ubuntu0.2 Ubuntu 24.04 LTS libxfont2 1:2.0.6-1+deb13u1build0.24.04.2 Ubuntu 22.04 LTS libxfont2 1:2.0.5-1ubuntu0.2 Ubuntu 20.04 LTS libxfont2 1:2.0.3-1ubuntu0.20.04.1~esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS libxfont2 1:2.0.3-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS libxfont1 1:1.5.1-1ubuntu0.16.04.4+esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS libxfont1 1:1.4.7-1ubuntu0.4+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8560-1 CVE-2017-16611, CVE-2026-56001, CVE-2026-56002, CVE-2026-56003 Package Information: https://launchpad.net/ubuntu/+source/libxfont/1:2.0.6-2ubuntu0.2 https://launchpad.net/ubuntu/+source/libxfont/1:2.0.6-1+deb13u1build0.24.04.2 https://launchpad.net/ubuntu/+source/libxfont/1:2.0.5-1ubuntu0.2 . Explore the critical updates for libXfont addressing denial of service issues and buffer overflows impacting various Ubuntu versions.. libXfont update, Ubuntu security patches, heap overflow fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 20, 2026 Important Ubuntu
87

Debian libXfont Important Code Execution Risks DSA-6388-1

Several vulnerabilities were discovered in libXfont, the X11 font rasterisation library, which may result in arbitrary code execution in the X server context for authenticated X clients. For the stable distribution (trixie), these problems have been fixed in version 1:2.0.6-1+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6388-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso July 15, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libxfont CVE ID : CVE-2026-56001 CVE-2026-56002 CVE-2026-56003 Debian Bug : 1141702 Several vulnerabilities were discovered in libXfont, the X11 font rasterisation library, which may result in arbitrary code execution in the X server context for authenticated X clients. For the stable distribution (trixie), these problems have been fixed in version 1:2.0.6-1+deb13u1. We recommend that you upgrade your libxfont packages. For the detailed security status of libxfont please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libxfont Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several critical issues in libXfont may lead to code execution; an upgrade is necessary for Debian users.. libXfont security issues, Debian advisory, code execution risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 15, 2026 Important Debian
197

Debian LTS libxfont Critical Heap Overflow Threat DLA-4678-1 CVE-2026-56001

A series of heap overflows in bitmap/PCF parser code could be used by authenticated attackers to execute code in the X server context. CVE-2026-56001 A heap buffer overflow in BitmapScaleBitmaps in due to an overflowing 32-bit size.. Debian LTS Advisory DLA-4678-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andrej Shadura July 12, 2026 https://wiki.debian.org/LTS Package : libxfont Version : 1:2.0.4-1+deb11u1 1:2.0.6-1+deb12u1 CVE ID : CVE-2026-56001 CVE-2026-56002 CVE-2026-56003 A series of heap overflows in bitmap/PCF parser code could be used by authenticated attackers to execute code in the X server context. CVE-2026-56001 A heap buffer overflow in BitmapScaleBitmaps in due to an overflowing 32-bit size. CVE-2026-56002 A heap bufferflow in pcfReadFont() due to missing glyph bounds checking. CVE-2026-56003 A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in ComputeScaledProperties(). For Debian 11 bullseye, these problems have been fixed in version 1:2.0.4-1+deb11u1. For Debian 12 bookworm, these problems have been fixed in version 1:2.0.6-1+deb12u1. We recommend that you upgrade your libxfont packages. For the detailed security status of libxfont please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libxfont Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Heap overflows in libxfont allow authenticated attackers to execute code in X server context. Update recommended.. libxfont update, heap overflow exploit, authenticated access risk, Debian LTS security, security patch guide. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 12, 2026 Critical Debian LTS
197

Debian: DLA-2901-1 Moderate: Libxfont Local File Access Threat

n issue has been found in libxfont, an X11 font rasterisation library. By creating symlinks, a local attacker can open (but not read) local files as user root. This might create unwanted actions with special files like . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2901-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz January 25, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libxfont Version : 1:2.0.1-3+deb9u2 CVE ID : CVE-2017-16611 n issue has been found in libxfont, an X11 font rasterisation library. By creating symlinks, a local attacker can open (but not read) local files as user root. This might create unwanted actions with special files like /dev/watchdog. For Debian 9 stretch, this problem has been fixed in version 1:2.0.1-3+deb9u2. We recommend that you upgrade your libxfont packages. For the detailed security status of libxfont please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libxfont Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2902-1 tackles local directory traversal flaw in libgraphics. Urgent upgrade is advised.. Debian LTS, libxfont, local access, security fix. . LinuxSecurity.com Team

Calendar%202 Jan 25, 2022 Debian LTS
89

CentOS 7: 2018-4512db3a1c Critical: libXrender Buffer Overflow Risk

Security fix for CVE-2017-13720 and CVE-2017-13722. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-2783ef2c63 2017-10-25 21:34:15.278005 --------------------------------------------------------------------------------Name : libXfont Product : Fedora 26 Version : 1.5.2 Release : 5.fc26 URL : https://www.x.org/wiki/ Summary : X.Org X11 libXfont runtime library Description : X.Org X11 libXfont runtime library --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-13720 and CVE-2017-13722 --------------------------------------------------------------------------------References: [ 1 ] Bug #1500693 - CVE-2017-13722 libXfont: Insufficient input validation in pcfread.c https://bugzilla.redhat.com/show_bug.cgi?id=1500693 [ 2 ] Bug #1500690 - CVE-2017-13720 libXfont: Insufficient input validation in fontdir.c https://bugzilla.redhat.com/show_bug.cgi?id=1500690 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libXfont' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora's libXfont has been updated to fix critical security vulnerabilities tied to inadequate input validation, ensuring enhanced system integrity. Fedora Security Update, libXfont, InputValidation Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 25, 2017 Critical Fedora
87

Debian: DSA-4002-1 Moderate: libXcursor Memory Leak and Denial of Service

Two vulnerabilities were found in libXfont, the X11 font rasterisation library, which could result in denial of service or memory disclosure. For the oldstable distribution (jessie), these problems have been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3995-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff October 10, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libxfont CVE ID : CVE-2017-13720 CVE-2017-13722 Two vulnerabilities were found in libXfont, the X11 font rasterisation library, which could result in denial of service or memory disclosure. For the oldstable distribution (jessie), these problems have been fixed in version 1:1.5.1-1+deb8u1. For the stable distribution (stretch), these problems have been fixed in version 1:2.0.1-3+deb9u1. We recommend that you upgrade your libxfont packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A pair of security flaws in libXfont for Debian have been patched to avert denial of service and memory management problems highlighted in the advisory.. libXfont Update, Debian Security, Memory Disclosure Fix, DoS Prevention. . LinuxSecurity.com Team

Calendar%202 Oct 10, 2017 Debian
197

Debian 7: DLA-1126-1 Critical: Libxfont Memory Access Threat

It was discovered that there two vulnerabilities the library providing font selection and rasterisation, libxfont: * CVE-2017-13720: If a pattern contained a '?' character any character . Hash: SHA256 Package : libxfont Version : 1:1.4.5-5+deb7u1 CVE IDs : CVE-2017-13720 CVE-2017-13722 It was discovered that there two vulnerabilities the library providing font selection and rasterisation, libxfont: * CVE-2017-13720: If a pattern contained a '?' character any character in the string is skipped even if it was a '\0'. The rest of the matching then read invalid memory. * CVE-2017-13722: A malformed PCF file could cause the library to make reads from random heap memory that was behind the `strings` buffer, leading to an application crash or a information leak. For Debian 7 "Wheezy", this issue has been fixed in libxfont version 1:1.4.5-5+deb7u1. We recommend that you upgrade your libxfont packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Enhance libxfont on Debian 7 to resolve two major vulnerabilities related to font processing and rendering.. Debian Security, libxfont, Memory Issues, Information Leak. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 07, 2017 Critical Debian LTS
172

Ubuntu 14.10: USN-2536-1 Moderate: libXfont Code Execution Risk

libXfont could be made to crash or run programs as an administrator if it opened a specially crafted bdf font file.. =========================================================================Ubuntu Security Notice USN-2536-1 March 18, 2015 libxfont vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: libXfont could be made to crash or run programs as an administrator if it opened a specially crafted bdf font file. Software Description: - libxfont: X11 font rasterisation library Details: Ilja van Sprundel, Alan Coopersmith, and William Robinet discovered that libXfont incorrectly handled malformed bdf fonts. A local attacker could use this issue to cause libXfont to crash, or possibly execute arbitrary code in order to gain privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: libxfont1 1:1.4.99.901-1ubuntu0.1 Ubuntu 14.04 LTS: libxfont1 1:1.4.7-1ubuntu0.2 Ubuntu 12.04 LTS: libxfont1 1:1.4.4-1ubuntu0.3 Ubuntu 10.04 LTS: libxfont1 1:1.4.1-1ubuntu0.4 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2536-1 CVE-2015-1802, CVE-2015-1803, CVE-2015-1804 Package Information: https://launchpad.net/ubuntu/+source/libxfont/1:1.4.99.901-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libxfont/1:1.4.7-1ubuntu0.2 https://launchpad.net/ubuntu/+source/libxfont/1:1.4.4-1ubuntu0.3 https://launchpad.net/ubuntu/+source/libxfont/1:1.4.1-1ubuntu0.4 . Enhance your Ubuntu installations to address libXfont security flaws that might result in system instability or illicit code execution..libxfont, ubuntu vulnerabilities, exploit fix, code execution. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 18, 2015 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200