Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34085

Опубликовано: 25 мар. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.

A flaw was found in fontconfig. This vulnerability, an off-by-one error in how fontconfig handles font capabilities, could allow a local attacker to cause a one-byte out-of-bounds write. This issue may lead to a system crash, resulting in a Denial of Service (DoS), or potentially enable the attacker to execute unauthorized code.

Отчет

This vulnerability is rated Moderate severity by Red Hat Product Security. The issue arises from a memory handling flaw in font processing, which can cause applications such as fc-cache to crash when processing a specially crafted font file. Exploitation requires a user to install or process a malicious font, meaning the issue cannot be triggered remotely without user interaction. While the crash may disrupt system functionality: for example, affecting graphical login services or applications that rely on font rendering, the impact is limited to application stability. The underlying flaw involves a very small memory overwrite (one byte), which significantly limits the ability to exploit it for more serious outcomes such as executing arbitrary code or fully compromising the system. There is no evidence that the vulnerability can be reliably used to gain control over a system or access sensitive data. Red Hat therefore assesses the primary impact as a denial of service in user-space components, resulting in a Moderate severity rating.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10fontconfigNot affected
Red Hat Enterprise Linux 6fontconfigOut of support scope
Red Hat Enterprise Linux 7fontconfigNot affected
Red Hat Enterprise Linux 8fontconfigNot affected
Red Hat Enterprise Linux 8mingw-fontconfigAffected
Red Hat Enterprise Linux 9fontconfigNot affected
Red Hat Hardened Imagesfontconfig-main-2.17.1-0.1.hum1FixedRHSA-2026:1372205.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=2451414fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash

EPSS

Процентиль: 3%
0.00125
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.

CVSS3: 5.9
nvd
4 месяца назад

fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.

msrc
4 месяца назад

fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.

CVSS3: 5.9
debian
4 месяца назад

fontconfig before 2.17.1 has an off-by-one error in allocation during ...

CVSS3: 5.9
github
4 месяца назад

fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.

EPSS

Процентиль: 3%
0.00125
Низкий

6.6 Medium

CVSS3