Logo
componentfreetype
Name
freetype
Version
2.13.3
Type
library
Description
-
Licenses
FTL or GPL-2.0+
PURL
-
CPE
cpe:2.3:a:freetype:freetype:2.13.3:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
2.14.3

Patches#


#
Title
Author
Resolve
1
[ttgxvar] Check for overflow in array size computation.
Werner Lemberg <wl@gnu.org>
CVE-2026-23865

Vulnerabilities#


Name
Analysis
Description
Patched
An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.