Описание
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
A flaw was found in fontconfig. This vulnerability, an off-by-one error in how fontconfig handles font capabilities, could allow a local attacker to cause a one-byte out-of-bounds write. This issue may lead to a system crash, resulting in a Denial of Service (DoS), or potentially enable the attacker to execute unauthorized code.
Отчет
This vulnerability is rated Moderate severity by Red Hat Product Security. The issue arises from a memory handling flaw in font processing, which can cause applications such as fc-cache to crash when processing a specially crafted font file. Exploitation requires a user to install or process a malicious font, meaning the issue cannot be triggered remotely without user interaction. While the crash may disrupt system functionality: for example, affecting graphical login services or applications that rely on font rendering, the impact is limited to application stability. The underlying flaw involves a very small memory overwrite (one byte), which significantly limits the ability to exploit it for more serious outcomes such as executing arbitrary code or fully compromising the system. There is no evidence that the vulnerability can be reliably used to gain control over a system or access sensitive data. Red Hat therefore assesses the primary impact as a denial of service in user-space components, resulting in a Moderate severity rating.
Меры по смягчению последствий
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | fontconfig | Not affected | ||
| Red Hat Enterprise Linux 6 | fontconfig | Out of support scope | ||
| Red Hat Enterprise Linux 7 | fontconfig | Not affected | ||
| Red Hat Enterprise Linux 8 | fontconfig | Not affected | ||
| Red Hat Enterprise Linux 8 | mingw-fontconfig | Affected | ||
| Red Hat Enterprise Linux 9 | fontconfig | Not affected | ||
| Red Hat Hardened Images | fontconfig-main-2.17.1-0.1.hum1 | Fixed | RHSA-2026:13722 | 05.05.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.6 Medium
CVSS3
Связанные уязвимости
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
fontconfig before 2.17.1 has an off-by-one error in allocation during ...
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
EPSS
6.6 Medium
CVSS3