Updated libxfont2 package fixes security vulnerabilities
Publication date: 08 Oct 2026Modification date: 08 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-59679 , CVE-2026-44950
Description
fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow
in libXfont2. (CVE-2026-44950)
fs_read_glyphs() heap OOB read/write via encoding array index mismatch
in libXfont2. (CVE-2026-59679)
References
- https://bugs.mageia.org/show_bug.cgi?id=36174
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NP3ZEUVKBUAKXYPBOSJNJAGWTMNRTSSG/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/PTGMTNHE2PKU34GA4TVT54ZYUWSQDO6P/
- https://www.cve.org/CVERecord?id=CVE-2026-59679
- https://www.cve.org/CVERecord?id=CVE-2026-44950
SRPMS
10/core
- libxfont2-2.0.9-1.mga10