CVE-2026-23865

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*
cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*

History

01 May 2026, 17:41

Type Values Removed Values Added
First Time Freetype
Freetype freetype
Summary
  • (es) Un desbordamiento de entero en la función tt_var_load_item_variation_store de la librería Freetype en las versiones 2.13.2 y 2.13.3 puede permitir una operación de lectura fuera de límites al analizar tablas HVAR/VVAR/MVAR en fuentes variables OpenType. Este problema está solucionado en la versión 2.14.2.
CPE cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*
References () https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c - () https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c - Patch
References () https://sourceforge.net/projects/freetype/files/freetype2/2.14.2/ - () https://sourceforge.net/projects/freetype/files/freetype2/2.14.2/ - Release Notes
References () https://www.facebook.com/security/advisories/cve-2026-23865 - () https://www.facebook.com/security/advisories/cve-2026-23865 - Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2026/03/03/8 - () http://www.openwall.com/lists/oss-security/2026/03/03/8 - Mailing List

04 Mar 2026, 01:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/03/8 -

02 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 17:16

Updated : 2026-05-01 17:41


NVD link : CVE-2026-23865

Mitre link : CVE-2026-23865

CVE.ORG link : CVE-2026-23865


JSON object : View

Products Affected

freetype

  • freetype
CWE
CWE-125

Out-of-bounds Read