Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21362-1

Опубликовано: 16 июл. 2026
Источник: suse-cvrf

Описание

Security update for freetype2

This update for freetype2 fixes the following issues

  • Update to version 2.14.3
  • CVE-2026-23865: Integer overflow in the tt_var_load_item_variation_store function (bsc#1259118).
  • CVE-2026-50811: out-of-bounds read vulnerabilityin src/truetype/ttgxvar.c in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates (bsc#1271045).

Список пакетов

openSUSE Leap 16.0
freetype2-devel-2.14.3-160000.1.1
freetype2-profile-tti35-2.14.3-160000.1.1
ft2demos-2.14.3-160000.1.1
ftbench-2.14.3-160000.1.1
ftdiff-2.14.3-160000.1.1
ftdump-2.14.3-160000.1.1
ftgamma-2.14.3-160000.1.1
ftgrid-2.14.3-160000.1.1
ftinspect-2.14.3-160000.1.1
ftlint-2.14.3-160000.1.1
ftmulti-2.14.3-160000.1.1
ftsdf-2.14.3-160000.1.1
ftstring-2.14.3-160000.1.1
ftvalid-2.14.3-160000.1.1
ftview-2.14.3-160000.1.1
libfreetype6-2.14.3-160000.1.1

Описание

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.


Затронутые продукты
openSUSE Leap 16.0:freetype2-devel-2.14.3-160000.1.1
openSUSE Leap 16.0:freetype2-profile-tti35-2.14.3-160000.1.1
openSUSE Leap 16.0:ft2demos-2.14.3-160000.1.1
openSUSE Leap 16.0:ftbench-2.14.3-160000.1.1

Ссылки

Описание

An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates


Затронутые продукты
openSUSE Leap 16.0:freetype2-devel-2.14.3-160000.1.1
openSUSE Leap 16.0:freetype2-profile-tti35-2.14.3-160000.1.1
openSUSE Leap 16.0:ft2demos-2.14.3-160000.1.1
openSUSE Leap 16.0:ftbench-2.14.3-160000.1.1

Ссылки