{"id":"AZL-92084","summary":"CVE-2026-56003 affecting package libXfont2 for versions less than 2.0.8-1","details":"A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.","modified":"2026-08-28T17:48:12.347223575Z","published":"2026-07-08T10:16:23Z","upstream":["CVE-2026-56003"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56003"}],"affected":[{"package":{"name":"libXfont2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libXfont2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.8-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92084.json"}}],"schema_version":"1.9.0"}