Skip to content
USN-8560-1: libXfont vulnerabilities

USN-8560-1: libXfont vulnerabilities

Ubuntu July 20, 2026

It was discovered that libXfont incorrectly handled scaling bitmap fonts, leading to a heap buffer overflow. An attacker able to access the X server could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-56001 ) It was discovered that libXfont did not properly check glyph bounds when reading PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-56002 ) It was discovered that libXfont did not properly check the size of the property buffer when parsing PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute...

It was discovered that libXfont incorrectly handled scaling bitmap fonts, leading to a heap buffer overflow. An attacker able to access the X server could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-56001 )

It was discovered that libXfont did not properly check glyph bounds when reading PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-56002 )

It was discovered that libXfont did not properly check the size of the property buffer when parsing PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute...

It was discovered that libXfont incorrectly handled scaling bitmap fonts, leading to a heap buffer overflow. An attacker able to access the X server could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-56001 ) It was discovered that libXfont did not properly check glyph bounds when reading PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-56002 ) It was discovered that libXfont did not properly check the size of the property buffer when parsing PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-56003 )

It was discovered that libXfont incorrectly handled scaling bitmap fonts, leading to a heap buffer overflow. An attacker able to access the X server could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-56001 )

It was discovered that libXfont did not properly check glyph bounds when reading PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-56002 )

It was discovered that libXfont did not properly check the size of the property buffer when parsing PCF fonts, leading to a heap buffer overflow. An authenticated X client could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-56003 )

In general, a standard system update will make all the necessary changes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.