CVE-2026-55999
ADVISORY - debianSummary
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
- xorg-server 2:21.1.24-1 (bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141703)
- xwayland 2:24.1.13-1 [trixie] - xwayland (Minor issue; Xwayland shouldn't be running as root) [bookworm] - xwayland (Minor issue; Xwayland shouldn't be running as root) https://www.openwall.com/lists/oss-security/2026/07/08/2 Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/fbf7bac22e2c6bd627fb042742a23318263edae1
EPSS Score: 0.00269 (0.192)
Common Weakness Enumeration (CWE)
ADVISORY - redhat
Buffer Access with Incorrect Length Value
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in