UbuntuUpdates.org

Package "libxfont"

Name: libxfont

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • X11 font rasterisation library (development headers)
  • X11 font rasterisation library

Latest version: 1:2.0.6-2ubuntu0.2
Release: resolute (26.04)
Level: security
Repository: main

Links



Other versions of "libxfont" in Resolute

Repository Area Version
base main 1:2.0.6-2
updates main 1:2.0.6-2ubuntu0.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1:2.0.6-2ubuntu0.2 2026-07-20 15:08:36 UTC

  libxfont (1:2.0.6-2ubuntu0.2) resolute-security; urgency=medium

  * Manage the security patches with quilt. The same fixes as 2ubuntu0.1 are
    applied, but as tracked patches rather than edits made directly to the
    upstream sources.
    - debian/patches/CVE-2026-56001.patch,
      debian/patches/CVE-2026-56002.patch,
      debian/patches/CVE-2026-56003.patch: add the patch files, which
      2ubuntu0.1 referenced in its changelog but did not ship.
    - debian/patches/series: list the three patches (was "# placeholder").
    - debian/control, debian/rules: build-depend on quilt and pass
      --with quilt to dh so the patches are applied at build time.
  * debian/patches/CVE-2026-56001.patch: additionally convert the
    "Couldn't allocate bitmaps" fprintf() to %zu instead of %d.

 -- John Breton <email address hidden> Thu, 16 Jul 2026 07:44:32 -0400

CVE-2026-56001 A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the
CVE-2026-56002 A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to exec
CVE-2026-56003 A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXf



About   -   Send Feedback to @ubuntu_updates