CVE-2026-23865
5.3
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Exploitability: 1.8 / Impact: 3.4
Source: cve-assign@fb.com (Secondary)
Description
An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.
Affected (2)
References (4)
Source: cve-assign@fb.com
Patch
Source: cve-assign@fb.com
Release Notes
Source: cve-assign@fb.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Timeline
No history available yet.