Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-23865

Опубликовано: 02 мар. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

РелизСтатусПримечание
devel

not-affected

2.14.1+dfsg-2ubuntu1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

released

2.13.2+dfsg-1ubuntu0.1
questing

released

2.13.3+dfsg-1ubuntu0.1
resolute

not-affected

2.14.1+dfsg-2ubuntu1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

ignored

superseded by openjdk-17
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

ignored

superseded by openjdk-17
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

17.0.19+10-1
esm-apps/bionic

released

17.0.19+10-1~18.04.2
esm-apps/focal

released

17.0.19+10-1~20.04.2
esm-apps/jammy

released

17.0.19+10-1~22.04.2
esm-apps/resolute

released

17.0.19+10-1~26.04.2
jammy

released

17.0.19+10-1~22.04.2
noble

released

17.0.19+10-1~24.04.2
questing

released

17.0.19+10-1~25.10.2
resolute

released

17.0.19+10-1~26.04.2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/resolute

released

17.0.19+10-0ubuntu1~26.04.1
jammy

DNE

noble

DNE

questing

released

17.0.19+10-0ubuntu1~25.10.1
resolute

released

17.0.19+10-0ubuntu1~26.04.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

ignored

superseded by openjdk-19
noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

21.0.11+10-1
esm-apps/focal

released

21.0.11+10-1~20.04.2
esm-apps/jammy

released

21.0.11+10-1~22.04.2
esm-apps/resolute

released

21.0.11+10-1~26.04.2
jammy

released

21.0.11+10-1~22.04.2
noble

released

21.0.11+10-1~24.04.2
questing

released

21.0.11+10-1~25.10.2
resolute

released

21.0.11+10-1~26.04.2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/resolute

released

21.0.11+10-0ubuntu1~26.04.1
jammy

DNE

noble

DNE

questing

released

21.0.11+10-0ubuntu1~25.10.1
resolute

released

21.0.11+10-0ubuntu1~26.04.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

25.0.3+9-2
jammy

released

25.0.3+9-2~22.04.2
noble

released

25.0.3+9-2~24.04.2
questing

released

25.0.3+9-2~25.10.2
resolute

released

25.0.3+9-2~26.04.2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/resolute

released

25.0.3+9-0ubuntu1~26.04.1
jammy

DNE

noble

DNE

questing

released

25.0.3+9-0ubuntu1~25.10.1
resolute

released

25.0.3+9-0ubuntu1~26.04.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

jammy

DNE

noble

DNE

questing

released

26.0.1+8-2~25.10.2
resolute

released

26.0.1+8-2~26.04.2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

released

8u492-ga~us2-0ubuntu1~18.04.1
esm-apps/focal

released

8u492-ga~us2-0ubuntu1~20.04.1
esm-apps/jammy

released

8u492-ga~us2-0ubuntu1~22.04.1
esm-apps/noble

released

8u492-ga~us2-0ubuntu1~24.04.1
esm-apps/resolute

released

8u492-ga~us2-0ubuntu1~26.04.1
esm-infra-legacy/xenial

released

8u492-ga~us2-0ubuntu1~16.04.1
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

8u492-ga~us2-0ubuntu1~22.04.1
noble

released

8u492-ga~us2-0ubuntu1~24.04.1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

ignored

no longer supported by upstream
esm-apps/xenial

ignored

end of ESM support, was ignored [no longer supported by upstream]
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

11.0.31+11-1ubuntu2
esm-apps/noble

released

11.0.31+11-1ubuntu1~24.04.2
esm-apps/resolute

released

11.0.31+11-1ubuntu1~26.04.2
esm-infra/bionic

released

11.0.31+11-1ubuntu1~18.04.2
esm-infra/focal

released

11.0.31+11-1ubuntu1~20.04.2
jammy

released

11.0.31+11-1ubuntu1~22.04.2
noble

released

11.0.31+11-1ubuntu1~24.04.2
questing

released

11.0.31+11-1ubuntu1~25.10.2
resolute

released

11.0.31+11-1ubuntu1~26.04.2
upstream

needs-triage

Показывать по

EPSS

Процентиль: 4%
0.00141
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
5 месяцев назад

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

CVSS3: 5.3
nvd
5 месяцев назад

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

CVSS3: 5.3
msrc
5 месяцев назад

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

CVSS3: 5.3
debian
5 месяцев назад

An integer overflow in the tt_var_load_item_variation_store function o ...

CVSS3: 5.3
github
5 месяцев назад

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

EPSS

Процентиль: 4%
0.00141
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2026-23865