libXfont2 2.0.9 is now available

This release contains the fixes for the issues reported in today's security 
advisory:
https://lists.x.org/archives/xorg-announce/2026-August/003734.html

- CVE-2026-59679: Font Server Client encoding Out-Of-Bounds Read/Write
- CVE-2026-44950: Font Server Client Cumulative Glyph Data Heap Buffer Overflow

Additionally, it changes a build-time default. Previously fontserver support
was compiled in by default unless --disable-fc was provided at configure time.
The new default is *disabled by default* unless --enable-fc is provided at
configure time. Doing so protects us from future fontserver-connection related
issues. Fontservers have been deprecated for many years and the vast majority
of users will not notice this changed default (Debian has built with
--disable-fc for years).

Peter Hutterer (5):
      README: fix documentation for --enable-snfformat
      Disable fontserver support by default
      fserve: validate num_chars against encoding array size in fs_read_glyphs
      fserve: bounds-check cumulative glyph data writes in fs_read_glyphs
      libXfont2 2.0.9

git tag: libXfont2-2.0.9

https://xorg.freedesktop.org/archive/individual/lib/libXfont2-2.0.9.tar.gz
SHA256: 8564b4df365bc5a6cb0c15900dc688f6e8f47b00a8571c6708c916dfb85066ba  
libXfont2-2.0.9.tar.gz
SHA512: 
00e8d574ad55e1c24a1d406611b479f0094935d5ae2444fe18b32c33c52ee33838d1eaaa22ea06eb356bc150fb8a103aabc95155bcbe5b58359683ff3ce999cf
  libXfont2-2.0.9.tar.gz
PGP:  
https://xorg.freedesktop.org/archive/individual/lib/libXfont2-2.0.9.tar.gz.sig

https://xorg.freedesktop.org/archive/individual/lib/libXfont2-2.0.9.tar.xz
SHA256: f042a370666815e7b941e9b7019024755bd1c6c2954afbfa515af378251799e2  
libXfont2-2.0.9.tar.xz
SHA512: 
ccd6d6abf6aa814a940d137813dba638f8259c3672abf00808d82df033c1026ae29d40c9068da4f112637338ad0d0fc15818a4afa9369a626c8f17e466b4fa72
  libXfont2-2.0.9.tar.xz
PGP:  
https://xorg.freedesktop.org/archive/individual/lib/libXfont2-2.0.9.tar.xz.sig

Attachment: signature.asc
Description: PGP signature

Reply via email to