Skip to content

CVE-2026-23865 on CTRL-OS 26.05

Aliases: CVE-2026-23865

Packages: freetype

Status: Resolved

Advisory Information

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

Updates

2026-08-01 00:56 CEST

Metadata changes:

  • Status for package freetype: “Resolved

2026-07-31 01:09 CEST

Metadata changes:

  • Status for package freetype: “New