git: aa41d353b04d - main - security/vuxml: Document multiple security issues in libXfont2

Kousuke Kannagi <[email protected]>
Newsgroups gmane.os.freebsd.devel.cvs.ports
Message-ID <[email protected]>
The branch main has been updated by mce:

URL: https://cgit.FreeBSD.org/ports/commit/?id=aa41d353b04d57b2829e088ef909950360a08fda

commit aa41d353b04d57b2829e088ef909950360a08fda
Author:     Kousuke Kannagi <[email protected]>
AuthorDate: 2026-08-07 15:37:12 +0000
Commit:     Kousuke Kannagi <[email protected]>
CommitDate: 2026-08-07 16:42:53 +0000

    security/vuxml: Document multiple security issues in libXfont2
    
    PR:             297327
    Approved by:    osa (mentor)
---
 security/vuxml/vuln/2026.xml | 30 ++++++++++++++++++++++++++++++
 1 file changed, 30 insertions(+)

diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index 1167d35e0e0f..4b425a1bb5c7 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,3 +1,33 @@
+  <vuln vid="1fae5869-9275-11f1-83e9-901b0e13f1a0">
+    <topic>libXfont2 -- multiple vulnerabilities</topic>
+    <affects>
+<package>
+<name>libXfont2</name>
+<range><lt>2.0.9</lt></range>
+</package>
+    </affects>
+    <description>
+	<body xmlns="http://www.w3.org/1999/xhtml">
+	<p>Zhixi "Jace" Sun, independent security researcher reports:</p>
+	<blockquote cite="https://lists.x.org/archives/xorg-announce/2026-August/003734.html">
+	  <ul>
+	    <li>CVE-2026-44950: Font Server Client Cumulative Glyph Data Heap Buffer Overflow</li>
+	    <li>CVE-2026-59679: Font Server Client encoding Out-Of-Bounds Read/Write</li>
+	  </ul>
+	</blockquote>
+	</body>
+    </description>
+    <references>
+      <cvename>CVE-2026-44950</cvename>
+      <cvename>CVE-2026-59679</cvename>
+      <url>https://lists.x.org/archives/xorg-announce/2026-August/003734.html</url>
+    </references>
+    <dates>
+      <discovery>2026-08-05</discovery>
+      <entry>2026-08-07</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="7e45952f-9268-11f1-ab2f-3c7c3fba4204">
     <topic>DNSDist, PowerDNS, PowerDNS Recursor -- vulnerability</topic>
     <affects>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.