CVE-2024-56732

NameCVE-2024-56732
DescriptionHarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1091529

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
harfbuzz (PTS)bullseye2.7.4-1fixed
bookworm6.0.0+dfsg-3fixed
trixie, sid10.1.0-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
harfbuzzsourcebullseye(not affected)
harfbuzzsourcebookworm(not affected)
harfbuzzsource(unstable)10.1.0-21091529

Notes

[bookworm] - harfbuzz <not-affected> (Vulnerable code introduced later)
[bullseye] - harfbuzz <not-affected> (Vulnerable code introduced later)
https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-qmp9-xqm5-jh6m
Fixed by: https://github.com/harfbuzz/harfbuzz/commit/1767f99e2e2196c3fcae27db6d8b60098d3f6d26 (main)

Search for package or bug name: Reporting problems