CVE-2026-55999Disclosure(x.org / x_server)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch x.org x_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • x_server
  • xwayland

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-08); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
x_serverxwayland

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-08: 2Mentions · 2026-07-27: 1Patch / Workaround · 2026-07-27: 1Technical Details · 2026-07-08: 207-0807-27
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-082
Disclosure1General1
2026-07-271
Patch1
Full discourse3 posts
  • XLibre@XLibreDev
    Patch

    We released the #XLibre Xserver 25.0.0.25, 25.1.9, and beta 25.2.2 during the last 4 days containing #security fixes for #CVE-2026-55999 and CVE-2026-56000. We recommend everyone update ASAP. https://github.com/X11Libre/xserver/releases/tag/xlibre-xserver-25.2.2 https://github.com/X11Libre/xserver/releases/tag/xlibre-xserver-25.1.9 https://github.com/X11Libre/xserver/releases/tag/xlibre-xserver-25.0.0.25

    Post summary

    XLibre Xserver released new versions that address CVE‑2026‑55999 and CVE‑2026‑56000, urging users to update promptly.

    324014423.2K
    5.3K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-55999 Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overf… https://www.cve.org/CVERecord?id=CVE-2026-55999 ----- Traducción: CVE-2026-55999 Ata… http://infoflow.cloud`

    Post summary

    The tweet shares a brief CVE description of a kernel‑related heap overflow in X servers but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000038
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55999 Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overf… https://www.cve.org/CVERecord?id=CVE-2026-55999

    Post summary

    CVE-2026-55999 describes a local heap buffer overflow in xorg-server and xwayland triggered by PCX fonts, affecting versions before 21.2.24 and 24.1.13, with no PoC, exploit, or patch information provided.

    00000671
    57.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appx.orgx_server---
Appx.orgxwayland---

Explore more