CVE-2026-50811

NameCVE-2026-50811
DescriptionAn out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1141704

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freetype (PTS)bullseye2.10.4+dfsg-1+deb11u1fixed
bullseye (security)2.10.4+dfsg-1+deb11u2fixed
bookworm, bookworm (security)2.12.1+dfsg-5+deb12u4fixed
trixie (security), trixie2.13.3+dfsg-1+deb13u1fixed
forky2.14.3+dfsg-1vulnerable
sid2.14.3+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freetypesourcebullseye(not affected)
freetypesourcebookworm(not affected)
freetypesourcetrixie(not affected)
freetypesource(unstable)2.14.3+dfsg-21141704

Notes

[trixie] - freetype <not-affected> (Vulnerable code introduced later)
[bookworm] - freetype <not-affected> (TT_Get_Var_Design OOB read introduced in 2.14.0; shipped code uses safe coords[i]=0)
[bullseye] - freetype <not-affected> (TT_Get_Var_Design OOB read introduced in 2.14.0; shipped code uses safe coords[i]=0)
https://gitlab.freedesktop.org/freetype/freetype/-/work_items/1436
Introduced with: https://gitlab.freedesktop.org/freetype/freetype/-/commit/f64c7db2fee3f5304df1cd722df72699736118f3 ( VER-2-14-0 )
Fixed by: https://gitlab.freedesktop.org/freetype/freetype/-/commit/8fa928f1617aba65f45b00f0dcb109f077b7741e
Fixed by: https://gitlab.freedesktop.org/freetype/freetype/-/commit/5a280ecde6f324de0d226261036e736e0cb49a71

Search for package or bug name: Reporting problems