CVE-2026-50811

NameCVE-2026-50811
DescriptionAn out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1141704

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freetype (PTS)bullseye2.10.4+dfsg-1+deb11u1fixed
bullseye (security)2.10.4+dfsg-1+deb11u2fixed
bookworm, bookworm (security)2.12.1+dfsg-5+deb12u4fixed
trixie (security), trixie2.13.3+dfsg-1+deb13u1vulnerable
forky, sid2.14.3+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freetypesourcebullseye(not affected)
freetypesourcebookworm(not affected)
freetypesource(unstable)(unfixed)1141704

Notes

[trixie] - freetype <no-dsa> (Minor issue)
[bookworm] - freetype <not-affected> (TT_Get_Var_Design OOB read introduced in 2.14.0; shipped code uses safe coords[i]=0)
[bullseye] - freetype <not-affected> (TT_Get_Var_Design OOB read introduced in 2.14.0; shipped code uses safe coords[i]=0)
https://gitlab.freedesktop.org/freetype/freetype/-/work_items/1436
Fixed by: https://gitlab.freedesktop.org/freetype/freetype/-/commit/5a280ecde6f324de0d226261036e736e0cb49a71

Search for package or bug name: Reporting problems