- What: Security update for libXfont2
- Impact: Systems using Red Hat Enterprise Linux affected
Red Hat Product Errata RHSA-2026:61995 - Security Advisory Issued: 2026-09-01 Updated: 2026-09-01 RHSA-2026:61995 - Security Advisory Overview Updated Packages Synopsis Important: libXfont2 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libXfont2 is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description X.Org X11 libXfont2 runtime library Security Fix(es): libxfont2: Font Server Client encoding[] Out-Of-Bounds Read/Write (CVE-2026-59679) libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client (CVE-2026-44950) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2509620 - CVE-2026-59679 libxfont2: Font Server Client encoding[] Out-Of-Bounds Read/Write BZ - 2509622 - CVE-2026-44950 libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client CVEs CVE-2026-44950 CVE-2026-59679 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 SRPM libXfont2-2.0.3-2.el8_4.2.src.rpm SHA-256: f21dc97304b870f2ded9b82a665b0aa506e271b14f3e3741aa32ed5a3669c5da x86_64 libXfont2-2.0.3-2.el8_4.2.i686.rpm SHA-256: a8bac869bfa6439f35219ed4f62d75b7dd178f34203a60b5202a8579ed2af0a0 libXfont2-2.0.3-2.el8_4.2.x86_64.rpm SHA-256: 913f6d3f21b5437e2c189a23b6c11f8a29d046fd47a8d4430f4fcf96c24844f9 libXfont2-debuginfo-2.0.3-2.el8_4.2.i686.rpm SHA-256: 2b2941482f52a8d8cc3adaebf10cba2ef15b8097405ffd6ff6cf5c1283237c86 libXfont2-debuginfo-2.0.3-2.el8_4.2.x86_64.rpm SHA-256: 854d1d3ffdea992da12d90bb60a43cd2ef9370965276cb54014a1bf321fe69b4 libXfont2-debugsource-2.0.3-2.el8_4.2.i686.rpm SHA-256: 7d3627dda9638973176c9da65b5e8fedc5f36c47095edab892963e784ca7e8ff libXfont2-debugsource-2.0.3-2.el8_4.2.x86_64.rpm SHA-256: b9d19a4ff09c01d08f12028a3209315d0982c978b3aa05f17fc1c82c4f5901c5 Red Hat Enterprise Linux Server - AUS 8.4 SRPM libXfont2-2.0.3-2.el8_4.2.src.rpm SHA-256: f21dc97304b870f2ded9b82a665b0aa506e271b14f3e3741aa32ed5a3669c5da x86_64 libXfont2-2.0.3-2.el8_4.2.i686.rpm SHA-256: a8bac869bfa6439f35219ed4f62d75b7dd178f34203a60b5202a8579ed2af0a0 libXfont2-2.0.3-2.el8_4.2.x86_64.rpm SHA-256: 913f6d3f21b5437e2c189a23b6c11f8a29d046fd47a8d4430f4fcf96c24844f9 libXfont2-debuginfo-2.0.3-2.el8_4.2.i686.rpm SHA-256: 2b2941482f52a8d8cc3adaebf10cba2ef15b8097405ffd6ff6cf5c1283237c86 libXfont2-debuginfo-2.0.3-2.el8_4.2.x86_64.rpm SHA-256: 854d1d3ffdea992da12d90bb60a43cd2ef9370965276cb54014a1bf321fe69b4 libXfont2-debugsource-2.0.3-2.el8_4.2.i686.rpm SHA-256: 7d3627dda9638973176c9da65b5e8fedc5f36c47095edab892963e784ca7e8ff libXfont2-debugsource-2.0.3-2.el8_4.2.x86_64.rpm SHA-256: b9d19a4ff09c01d08f12028a3209315d0982c978b3aa05f17fc1c82c4f5901c5 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .