CVE-2026-55999
X.Org xorg-server, xwayland, x server
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
- CVSS
- 7.8
- EPSS
- 0.21% 11.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.08