Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-0943

Опубликовано: 19 янв. 2026
Источник: debian
EPSS Низкий

Описание

HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.  Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libharfbuzz-shaper-perlnot-affectedpackage

Примечания

  • Debian packaging HarfBuzz strips sources from upstream tarball since initial

  • upload to the archive.

  • https://lists.security.metacpan.org/cve-announce/msg/36208377/

EPSS

Процентиль: 34%
0.00141
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.

CVSS3: 7.5
nvd
3 месяца назад

HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.  Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.

CVSS3: 7.5
github
3 месяца назад

HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.  Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.

EPSS

Процентиль: 34%
0.00141
Низкий