Red Hat Product Errata RHSA-2026:47079 - Security Advisory Issued: 2026-07-28 Updated: 2026-07-28 RHSA-2026:47079 - Security Advisory Overview Updated Packages Synopsis Important: libXfont2 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libXfont2 is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description X.Org X11 libXfont2 runtime library Security Fix(es): libXfont2: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow (CVE-2026-56001) libXfont2: PCF Font Parsing Heap Buffer Overflow (CVE-2026-56002) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2496640 - CVE-2026-56001 libXfont2: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow BZ - 2496641 - CVE-2026-56002 libXfont2: PCF Font Parsing Heap Buffer Overflow CVEs CVE-2026-56001 CVE-2026-56002 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM libXfont2-2.0.6-5.el10_2.1.src.rpm SHA-256: 3c730c49c918890f2119040b27c3aae2eb8d7550b723f1da44106087f6466299 x86_64 libXfont2-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 2069767201d72241e60dbbd3a62bbf1e2d80c0c74a4462d4873b8b73496439b7 libXfont2-debuginfo-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 5720fb30b5163ad5df7461dec1c03187131e3e94e832b94c65a95ebf37fe8e7b libXfont2-debugsource-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 57e65a5516066b8ef3b785a0def8ba864eaeb9be46a120aba0917b5cbb464044 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM libXfont2-2.0.6-5.el10_2.1.src.rpm SHA-256: 3c730c49c918890f2119040b27c3aae2eb8d7550b723f1da44106087f6466299 x86_64 libXfont2-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 2069767201d72241e60dbbd3a62bbf1e2d80c0c74a4462d4873b8b73496439b7 libXfont2-debuginfo-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 5720fb30b5163ad5df7461dec1c03187131e3e94e832b94c65a95ebf37fe8e7b libXfont2-debugsource-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 57e65a5516066b8ef3b785a0def8ba864eaeb9be46a120aba0917b5cbb464044 Red Hat Enterprise Linux for IBM z Systems 10 SRPM libXfont2-2.0.6-5.el10_2.1.src.rpm SHA-256: 3c730c49c918890f2119040b27c3aae2eb8d7550b723f1da44106087f6466299 s390x libXfont2-2.0.6-5.el10_2.1.s390x.rpm SHA-256: 40304b283ccee229f1a7389f740d5d6d518c520d371b314e8494fae56ebeaf8e libXfont2-debuginfo-2.0.6-5.el10_2.1.s390x.rpm SHA-256: 2f3e2d2ba9303a4a1ee31f7daa1aa9e1a253a5a1c3a342143637ed0ccdb57a48 libXfont2-debugsource-2.0.6-5.el10_2.1.s390x.rpm SHA-256: 68924e79764991fadde41ce0d9cc326d72cd1964d8745f343bbc40991e5c8b53 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM libXfont2-2.0.6-5.el10_2.1.src.rpm SHA-256: 3c730c49c918890f2119040b27c3aae2eb8d7550b723f1da44106087f6466299 s390x libXfont2-2.0.6-5.el10_2.1.s390x.rpm SHA-256: 40304b283ccee229f1a7389f740d5d6d518c520d371b314e8494fae56ebeaf8e libXfont2-debuginfo-2.0.6-5.el10_2.1.s390x.rpm SHA-256: 2f3e2d2ba9303a4a1ee31f7daa1aa9e1a253a5a1c3a342143637ed0ccdb57a48 libXfont2-debugsource-2.0.6-5.el10_2.1.s390x.rpm SHA-256: 68924e79764991fadde41ce0d9cc326d72cd1964d8745f343bbc40991e5c8b53 Red Hat Enterprise Linux for Power, little endian 10 SRPM libXfont2-2.0.6-5.el10_2.1.src.rpm SHA-256: 3c730c49c918890f2119040b27c3aae2eb8d7550b723f1da44106087f6466299 ppc64le libXfont2-2.0.6-5.el10_2.1.ppc64le.rpm SHA-256: a7c9803b204e2b0bfc59b90bf97fc329c08989626ccc601563561f9be958d462 libXfont2-debuginfo-2.0.6-5.el10_2.1.ppc64le.rpm SHA-256: 91a08b0e9f9dd892addf7526e4527f5603123e90b38597e81ece968646874054 libXfont2-debugsource-2.0.6-5.el10_2.1.ppc64le.rpm SHA-256: 3dbd6a57ac636a2a0f742f9e4159865ccefea3c61f7e8e0e63a7479e591a13e9 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM libXfont2-2.0.6-5.el10_2.1.src.rpm SHA-256: 3c730c49c918890f2119040b27c3aae2eb8d7550b723f1da44106087f6466299 ppc64le libXfont2-2.0.6-5.el10_2.1.ppc64le.rpm SHA-256: a7c9803b204e2b0bfc59b90bf97fc329c08989626ccc601563561f9be958d462 libXfont2-debuginfo-2.0.6-5.el10_2.1.ppc64le.rpm SHA-256: 91a08b0e9f9dd892addf7526e4527f5603123e90b38597e81ece968646874054 libXfont2-debugsource-2.0.6-5.el10_2.1.ppc64le.rpm SHA-256: 3dbd6a57ac636a2a0f742f9e4159865ccefea3c61f7e8e0e63a7479e591a13e9 Red Hat Enterprise Linux for ARM 64 10 SRPM libXfont2-2.0.6-5.el10_2.1.src.rpm SHA-256: 3c730c49c918890f2119040b27c3aae2eb8d7550b723f1da44106087f6466299 aarch64 libXfont2-2.0.6-5.el10_2.1.aarch64.rpm SHA-256: c6b8ef52c3c66de790894aece2543c93bbc949a2b57e510e1523b42d88c02094 libXfont2-debuginfo-2.0.6-5.el10_2.1.aarch64.rpm SHA-256: c844b4aa83cc8eb04f59c28639b28fc3e5c059afbe763a47db856340cacaf3b9 libXfont2-debugsource-2.0.6-5.el10_2.1.aarch64.rpm SHA-256: a4042fc9fe025d8a3dbb711ba4da9a62595bab75c0484e554f3a5fd07c853317 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM libXfont2-2.0.6-5.el10_2.1.src.rpm SHA-256: 3c730c49c918890f2119040b27c3aae2eb8d7550b723f1da44106087f6466299 aarch64 libXfont2-2.0.6-5.el10_2.1.aarch64.rpm SHA-256: c6b8ef52c3c66de790894aece2543c93bbc949a2b57e510e1523b42d88c02094 libXfont2-debuginfo-2.0.6-5.el10_2.1.aarch64.rpm SHA-256: c844b4aa83cc8eb04f59c28639b28fc3e5c059afbe763a47db856340cacaf3b9 libXfont2-debugsource-2.0.6-5.el10_2.1.aarch64.rpm SHA-256: a4042fc9fe025d8a3dbb711ba4da9a62595bab75c0484e554f3a5fd07c853317 Red Hat CodeReady Linux Builder for x86_64 10 SRPM x86_64 libXfont2-debuginfo-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 5720fb30b5163ad5df7461dec1c03187131e3e94e832b94c65a95ebf37fe8e7b libXfont2-debugsource-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 57e65a5516066b8ef3b785a0def8ba864eaeb9be46a120aba0917b5cbb464044 libXfont2-devel-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 4f22a4a6226808a06bbefbaac4b4946cc9732907466b235226716b3cedac6546 Red Hat CodeReady Linux Builder for Power, little endian 10 SRPM ppc64le libXfont2-debuginfo-2.0.6-5.el10_2.1.ppc64le.rpm SHA-256: 91a08b0e9f9dd892addf7526e4527f5603123e90b38597e81ece968646874054 libXfont2-debugsource-2.0.6-5.el10_2.1.ppc64le.rpm SHA-256: 3dbd6a57ac636a2a0f742f9e4159865ccefea3c61f7e8e0e63a7479e591a13e9 libXfont2-devel-2.0.6-5.el10_2.1.ppc64le.rpm SHA-256: 8fbdb258054f69d6f0cec0d1f568da16b35b51b70f5e554acd797fd9603b9f72 Red Hat CodeReady Linux Builder for ARM 64 10 SRPM aarch64 libXfont2-debuginfo-2.0.6-5.el10_2.1.aarch64.rpm SHA-256: c844b4aa83cc8eb04f59c28639b28fc3e5c059afbe763a47db856340cacaf3b9 libXfont2-debugsource-2.0.6-5.el10_2.1.aarch64.rpm SHA-256: a4042fc9fe025d8a3dbb711ba4da9a62595bab75c0484e554f3a5fd07c853317 libXfont2-devel-2.0.6-5.el10_2.1.aarch64.rpm SHA-256: cd1b03fb8e05aae1dbdc0c47cd3bc4e32ff469d9b0c650d0ccbde506c4edb552 Red Hat CodeReady Linux Builder for IBM z Systems 10 SRPM s390x libXfont2-debuginfo-2.0.6-5.el10_2.1.s390x.rpm SHA-256: 2f3e2d2ba9303a4a1ee31f7daa1aa9e1a253a5a1c3a342143637ed0ccdb57a48 libXfont2-debugsource-2.0.6-5.el10_2.1.s390x.rpm SHA-256: 68924e79764991fadde41ce0d9cc326d72cd1964d8745f343bbc40991e5c8b53 libXfont2-devel-2.0.6-5.el10_2.1.s390x.rpm SHA-256: bd96a12540d039ef7aa055a11392a9ac52d8f242daf8bf126d67cf756d03fcb1 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 SRPM x86_64 libXfont2-debuginfo-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 5720fb30b5163ad5df7461dec1c03187131e3e94e832b94c65a95ebf37fe8e7b libXfont2-debugsource-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 57e65a5516066b8ef3b785a0def8ba864eaeb9be46a120aba0917b5cbb464044 libXfont2-devel-2.0.6-5.el10_2.1.x86_64.rpm SHA-256: 4f22a4a6226808a06bbefbaac4b4946cc9732907466b235226716b3cedac6546 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 SRPM ppc64le libXfont2-debuginfo-2.0.6-5.el10_
Two critical heap buffer overflow vulnerabilities (CVE-2026-56001 and CVE-2026-56002, both CVSS 8.5 HIGH) in the libXfont2 library allow for potential code execution via integer overflow during bitmap scaling or parsing of malicious PCF font files. Affected versions are libXfont2 from 2.0.0 through versions prior to 2.0.8. The fix is to upgrade libXfont2 to version 2.0.8.