Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:51063 - Security Advisory
Issued:
2026-08-06
Updated:
2026-08-06

RHSA-2026:51063 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libXfont2 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libXfont2 is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

X.Org X11 libXfont2 runtime library

Security Fix(es):

  • libXfont2: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow (CVE-2026-56001)
  • libXfont2: PCF Font Parsing Heap Buffer Overflow (CVE-2026-56002)
  • libXfont2: computeProps Property Buffer Heap Buffer Overflow (CVE-2026-56003)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2496640 - CVE-2026-56001 libXfont2: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
  • BZ - 2496641 - CVE-2026-56002 libXfont2: PCF Font Parsing Heap Buffer Overflow
  • BZ - 2496642 - CVE-2026-56003 libXfont2: computeProps Property Buffer Heap Buffer Overflow

CVEs

  • CVE-2026-56001
  • CVE-2026-56002
  • CVE-2026-56003

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
libXfont2-2.0.3-2.el7_9.src.rpm SHA-256: 51d0f0642f4bea2bbe0738a857275a4682ebd45f99a7bedc7e0cbf6fc9cb3189
x86_64
libXfont2-2.0.3-2.el7_9.i686.rpm SHA-256: d8dbcf87f708aa509cf8be57c87c61e574735e196b222d6c858106d3dbcf1002
libXfont2-2.0.3-2.el7_9.x86_64.rpm SHA-256: f0a17c9aecf0c4acf65317a78c564f5f9859d086140185ff07ded287ac9e96e1
libXfont2-debuginfo-2.0.3-2.el7_9.i686.rpm SHA-256: 0f5d375138bb5322ecccab28222366b2d0fb44a517cfea8201a803a1008bd6e4
libXfont2-debuginfo-2.0.3-2.el7_9.i686.rpm SHA-256: 0f5d375138bb5322ecccab28222366b2d0fb44a517cfea8201a803a1008bd6e4
libXfont2-debuginfo-2.0.3-2.el7_9.x86_64.rpm SHA-256: b4386c8bab5144f56d8645b8c2eaee19e23d9f3c0f1fdc3355de7e6463d0e46a
libXfont2-debuginfo-2.0.3-2.el7_9.x86_64.rpm SHA-256: b4386c8bab5144f56d8645b8c2eaee19e23d9f3c0f1fdc3355de7e6463d0e46a
libXfont2-devel-2.0.3-2.el7_9.i686.rpm SHA-256: 337c806888ec02d334117a8e677c9141fe38f894e94119e2fb809634f1be2945
libXfont2-devel-2.0.3-2.el7_9.x86_64.rpm SHA-256: 98d86226b4eec97c2494318d866d231ed58137e49c779caca8d2ef4f13007f7b

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
libXfont2-2.0.3-2.el7_9.src.rpm SHA-256: 51d0f0642f4bea2bbe0738a857275a4682ebd45f99a7bedc7e0cbf6fc9cb3189
s390x
libXfont2-2.0.3-2.el7_9.s390.rpm SHA-256: 417c030d69d52d801e947b215d02861e1dd0ce285b61f1971dc329e2b6cbe93c
libXfont2-2.0.3-2.el7_9.s390x.rpm SHA-256: 90bb2a5dd7fb608b3e27cbec0a8c6a3977525ded60d23e78d62203cfbc7a5c93
libXfont2-debuginfo-2.0.3-2.el7_9.s390.rpm SHA-256: 10a914bd40871014b47d95816f204a216f1b1ef4ed81465b8dcd9bd8ec4acde0
libXfont2-debuginfo-2.0.3-2.el7_9.s390.rpm SHA-256: 10a914bd40871014b47d95816f204a216f1b1ef4ed81465b8dcd9bd8ec4acde0
libXfont2-debuginfo-2.0.3-2.el7_9.s390x.rpm SHA-256: b223498f671489e24ea2af055d6b89ec33f0ab51957cfdb473c6e050e6a45d46
libXfont2-debuginfo-2.0.3-2.el7_9.s390x.rpm SHA-256: b223498f671489e24ea2af055d6b89ec33f0ab51957cfdb473c6e050e6a45d46
libXfont2-devel-2.0.3-2.el7_9.s390.rpm SHA-256: 3b3b8416904589ce49aa9f6d0ab12c00a4ef4c3fa7a0b004851aea3f27515657
libXfont2-devel-2.0.3-2.el7_9.s390x.rpm SHA-256: 7ff84d35a271673a3b2899a133505f43a0451b1b0d46870771dc314e4ef53da5

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
libXfont2-2.0.3-2.el7_9.src.rpm SHA-256: 51d0f0642f4bea2bbe0738a857275a4682ebd45f99a7bedc7e0cbf6fc9cb3189
ppc64
libXfont2-2.0.3-2.el7_9.ppc.rpm SHA-256: 50681311e4028e0e0c6a98ccf0baf317faf57d8ad3f65542e892be6af6755957
libXfont2-2.0.3-2.el7_9.ppc64.rpm SHA-256: d149f4773477856fa8aa15de0214eb9ca9a6acabb7c60ad44f4f94cc71152c1d
libXfont2-debuginfo-2.0.3-2.el7_9.ppc.rpm SHA-256: d4f9fec15bde60497e999b7e3560df8a760f37a8830fbfbfa1572dfd90492894
libXfont2-debuginfo-2.0.3-2.el7_9.ppc.rpm SHA-256: d4f9fec15bde60497e999b7e3560df8a760f37a8830fbfbfa1572dfd90492894
libXfont2-debuginfo-2.0.3-2.el7_9.ppc64.rpm SHA-256: d89bd5e540dea06c13f00a5274e156de6e8baff45d22577a68cc754b50a790ab
libXfont2-debuginfo-2.0.3-2.el7_9.ppc64.rpm SHA-256: d89bd5e540dea06c13f00a5274e156de6e8baff45d22577a68cc754b50a790ab
libXfont2-devel-2.0.3-2.el7_9.ppc.rpm SHA-256: 044d66f460704d57900986af41f19fc830324bcf096a7158137ad802300fbe00
libXfont2-devel-2.0.3-2.el7_9.ppc64.rpm SHA-256: 41eba746deca610286764521b6146bb3279c9a6873cccc6ae79470ab1d24187c

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
libXfont2-2.0.3-2.el7_9.src.rpm SHA-256: 51d0f0642f4bea2bbe0738a857275a4682ebd45f99a7bedc7e0cbf6fc9cb3189
ppc64le
libXfont2-2.0.3-2.el7_9.ppc64le.rpm SHA-256: f4b41f2e74748fd136f1ad74e043cb4e027c3281f5f1f5bbff7ca9163a733d27
libXfont2-debuginfo-2.0.3-2.el7_9.ppc64le.rpm SHA-256: 22b16e4e7dc2ef3c334edca59de371ca489e8a0232c070a7d782694803520c1b
libXfont2-debuginfo-2.0.3-2.el7_9.ppc64le.rpm SHA-256: 22b16e4e7dc2ef3c334edca59de371ca489e8a0232c070a7d782694803520c1b
libXfont2-devel-2.0.3-2.el7_9.ppc64le.rpm SHA-256: 46cbaf37e2c334d1b72338a53a70f634e5051c838fe8f99dfb4b17b313e4472c

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility