CVE-2026-23865

Published: March 6, 2026Last modified: March 13, 2026

Description

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

Severity score breakdown

ParameterValue
Base score5.3
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSfreetypeUnknown (2.12.1-r0)
25 LTSfreetypeUnknown (2.13.3-r0)
StreamfreetypeFixed (2.14.2-r0)
Hardened Containers23 LTSfreetypeUnknown (2.12.1-r0)
25 LTSfreetypeUnknown (2.13.3-r0)
StreamfreetypeUnknown (2.13.0-r6)

References

ON THIS PAGE