CVE-2026-23865

NameCVE-2026-23865
DescriptionAn integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freetype (PTS)bullseye2.10.4+dfsg-1+deb11u1vulnerable
bullseye (security)2.10.4+dfsg-1+deb11u2vulnerable
bookworm, bookworm (security)2.12.1+dfsg-5+deb12u4vulnerable
trixie2.13.3+dfsg-1vulnerable
forky, sid2.14.1+dfsg-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freetypesource(unstable)(unfixed)

Notes

Fixed by: https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c (VER-2-14-2)

Search for package or bug name: Reporting problems