[CLSA-2026:1789382915] libXfont2: Fix of 3 CVEs
Type:
security
Severity:
None
Release date:
2026-09-14 10:48:45 UTC
Description:
- Rebase onto vendor 2.0.3-1.amzn2.0.2 - Fix CVE-2026-44950: out-of-bounds write from unvalidated cumulative glyph data writes in src/fc/fserve.c - Fix CVE-2026-59679: out-of-bounds access from num_chars not validated against the encoding array size in src/fc/fserve.c - Drop our CVE-2026-56001/56002/56003 patches in favour of the vendor's Fix-ZDI-CAN-30558/30559/30560, which carry the same upstream fixes
Updated packages:
  • libXfont2-2.0.3-1.amzn2.0.2.tuxcare.els4.i686.rpm
    sha:0defd68e5f95d918b2f74762bb84b439312eea3a6c5e348fade6772aa9e7f274
  • libXfont2-2.0.3-1.amzn2.0.2.tuxcare.els4.x86_64.rpm
    sha:234df9c009b96b7328062b5f588a887ce2f73e98106a06c264a493384cded672
  • libXfont2-devel-2.0.3-1.amzn2.0.2.tuxcare.els4.x86_64.rpm
    sha:2cb352d88ffa66e52592cf32e7176125714848c9e869417072b55d10a745a406
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.