REDHAT-BUG-2443891: Integer Overflow
Published Mar 2, 2026
·Updated
An integer overflow in the ttvarloaditemvariationstore function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.
Affected Software
1 affected component
FreeType FreeType>=2.13.2<=2.13.3
Event History
Mar 2, 2026
Data Sourced
via Red Hat·05:03 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2443891?
The severity of REDHAT-BUG-2443891 is medium (4).
2
How do I fix REDHAT-BUG-2443891?
To fix REDHAT-BUG-2443891, upgrade to FreeType version 2.14.2 or later.
3
What is the cause of REDHAT-BUG-2443891?
REDHAT-BUG-2443891 is caused by an integer overflow in the tt_var_load_item_variation_store function of the FreeType library.
4
In which versions of FreeType is REDHAT-BUG-2443891 present?
REDHAT-BUG-2443891 is present in FreeType versions 2.13.2 and 2.13.3.
5
What type of vulnerability is REDHAT-BUG-2443891?
REDHAT-BUG-2443891 is classified as an Integer Overflow vulnerability.