CVE-2026-23865: Announcing FeType 2.14.2, fixes CVE-2026-23865
An integer overflow in the ttvarloaditemvariationstore function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/freetypeto a version that resolves this vulnerability.Fixed in 2.10.4+dfsg-1+deb11u1Fixed in 2.10.4+dfsg-1+deb11u2Fixed in 2.12.1+dfsg-5+deb12u4Fixed in 2.13.3+dfsg-1+deb13u1Fixed in 2.14.3+dfsg-1 - Upgrade
Upgrade
Freetype libraryto a version that resolves this vulnerability.Fixed in 2.14.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23865?
The severity of CVE-2026-23865 is considered high due to the potential for out of bounds read operations.
How do I fix CVE-2026-23865?
To fix CVE-2026-23865, you should upgrade to FreeType version 2.14.2 or later.
Which versions of FreeType are affected by CVE-2026-23865?
FreeType versions 2.13.2 and 2.13.3 are affected by CVE-2026-23865.
What causes CVE-2026-23865?
CVE-2026-23865 is caused by an integer overflow in the tt_var_load_item_variation_store function when parsing OpenType variable fonts.
What impact does CVE-2026-23865 have on systems?
CVE-2026-23865 may lead to out of bounds read operations, potentially allowing attackers to read sensitive data.