← Back

CVE-2026-23865

nvd nist
Published: Mar 2, 2026Modified: May 1, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Exploitability: 1.8 / Impact: 3.4
Source: cve-assign@fb.com (Secondary)

Description

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

Affected (2)

Products: Freetype: Freetype
1 product
Freetype
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Freetype
From 2.13.2 to 2.13.3
From 2.14.0 to 2.14.1

References (4)

Timeline

No history available yet.