Release date:
2026-09-14 10:48:45 UTC
Description:
- Rebase onto vendor 2.0.3-1.amzn2.0.2
- Fix CVE-2026-44950: out-of-bounds write from unvalidated cumulative glyph
data writes in src/fc/fserve.c
- Fix CVE-2026-59679: out-of-bounds access from num_chars not validated
against the encoding array size in src/fc/fserve.c
- Drop our CVE-2026-56001/56002/56003 patches in favour of the vendor's
Fix-ZDI-CAN-30558/30559/30560, which carry the same upstream fixes
Updated packages:
-
libXfont2-2.0.3-1.amzn2.0.2.tuxcare.els4.i686.rpm
sha:0defd68e5f95d918b2f74762bb84b439312eea3a6c5e348fade6772aa9e7f274
-
libXfont2-2.0.3-1.amzn2.0.2.tuxcare.els4.x86_64.rpm
sha:234df9c009b96b7328062b5f588a887ce2f73e98106a06c264a493384cded672
-
libXfont2-devel-2.0.3-1.amzn2.0.2.tuxcare.els4.x86_64.rpm
sha:2cb352d88ffa66e52592cf32e7176125714848c9e869417072b55d10a745a406
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.