yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2018-19876
Component Overview
Vulnerability Overview
Name
CVE-2018-19876
Source
NVD (
link
)
Debian (
link
)
Description
cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid pointer" error.
CWEs
CWE-416
Published Date
Dec 5, 2018
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugs.webkit.org/show_bug.cgi?id=191595
Issue Tracking
https://gitlab.freedesktop.org/cairo/cairo/merge_requests/5
Patch
https://bugs.webkit.org/show_bug.cgi?id=191595
Issue Tracking
https://gitlab.freedesktop.org/cairo/cairo/merge_requests/5
Patch
Analysis
#
Affected Component
Analysis
cairo
Patched
Vulnerability Ratings
#
6.5
other
4.3
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
cairo
buildroot
2025.02.x
1.18.4
Not Affected
cairo
buildroot
master
1.18.4
Not Affected
cairo
yocto
master
1.18.4
Not Affected
cairo
yocto
scarthgap
1.18.0
Not Affected
Resolved with patches
#
cairo (yocto:kirkstone)
#
Title
Author
Resolve
1
ft: Use FT_Done_MM_Var instead of free when available in
Carlos Garcia Campos <cgarcia@igalia.com>
CVE-2018-19876