Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-22693

7 месяцев назад

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-22693

7 месяцев назад

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-22693

7 месяцев назад

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-22693

7 месяцев назад

Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-22693

7 месяцев назад

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null poi ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20409-1

5 месяцев назад

Security update for harfbuzz

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0287-1

7 месяцев назад

Security update for harfbuzz

EPSS: Низкий
fstec логотип

BDU:2026-06703

7 месяцев назад

Уязвимость функции SubtableUnicodesCache::create() компонента src/hb-ot-cmap-table.hh библиотеки для преобразования текста HarfBuzz, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-22693

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
redhat логотип
CVE-2026-22693

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2026-22693

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
msrc логотип
CVE-2026-22693

Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS

CVSS3: 5.3
0%
Низкий
7 месяцев назад
debian логотип
CVE-2026-22693

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null poi ...

CVSS3: 5.3
0%
Низкий
7 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20409-1

Security update for harfbuzz

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0287-1

Security update for harfbuzz

0%
Низкий
7 месяцев назад
fstec логотип
BDU:2026-06703

Уязвимость функции SubtableUnicodesCache::create() компонента src/hb-ot-cmap-table.hh библиотеки для преобразования текста HarfBuzz, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
0%
Низкий
7 месяцев назад

Уязвимостей на страницу