{"id":"AZL-92087","summary":"CVE-2026-56002 affecting package libXfont2 for versions less than 2.0.8-1","details":"A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.","modified":"2026-08-28T17:48:12.347161459Z","published":"2026-07-08T10:16:23Z","upstream":["CVE-2026-56002"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56002"}],"affected":[{"package":{"name":"libXfont2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libXfont2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.8-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92087.json"}}],"schema_version":"1.9.0"}