fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
References
Configurations
History
27 Mar 2026, 21:39
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:fontconfig_project:fontconfig:*:*:*:*:*:*:*:* | |
| References | () https://gitlab.freedesktop.org/fontconfig/fontconfig/-/commit/b9bec06d73340f1b5727302d13ac3df307b7febc - Patch | |
| References | () https://gitlab.freedesktop.org/fontconfig/fontconfig/-/merge_requests/446 - Patch | |
| References | () https://gitlab.freedesktop.org/fontconfig/fontconfig/-/work_items/481 - Issue Tracking | |
| Summary |
|
|
| First Time |
Fontconfig Project
Fontconfig Project fontconfig |
25 Mar 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-25 17:17
Updated : 2026-03-27 21:39
NVD link : CVE-2026-34085
Mitre link : CVE-2026-34085
CVE.ORG link : CVE-2026-34085
JSON object : View
Products Affected
fontconfig_project
- fontconfig
CWE
CWE-193
Off-by-one Error
