yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-27404
Component Overview
Vulnerability Overview
Name
CVE-2022-27404
Source
NVD (
link
)
Debian (
link
)
Description
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
CWEs
CWE-787
Published Date
Apr 22, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gitlab.freedesktop.org/freetype/freetype/-/issues/1138
Exploit
https://gitlab.freedesktop.org/freetype/freetype/-/issues/1138
Exploit
Analysis
#
Affected Component
Analysis
freetype
Exploitable
Vulnerability Ratings
#
9.8
CVSSv31
7.5
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
freetype
buildroot
2025.02.x
2.13.3
Not Affected
freetype
buildroot
master
2.14.3
Not Affected
freetype
openwrt
master
2.13.3-r2
Not Affected
freetype
openwrt
openwrt-25.12
2.13.3-r1
Not Affected
freetype
yocto
master
2.14.3
Not Affected
freetype
yocto
scarthgap
2.13.2
Not Affected