yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-25193
Component Overview
Vulnerability Overview
Name
CVE-2023-25193
Source
NVD (
link
)
Debian (
link
)
Description
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
CWEs
CWE-770
CWE-770
Published Date
Feb 4, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://chromium.googlesource.com/chromium/src/+/e1f324aa681af54101c1f2d173d92adb80e37088/DEPS#361
Patch
https://github.com/harfbuzz/harfbuzz/blob/2822b589bc837fae6f66233e2cf2eef0f6ce8470/src/hb-ot-layout-gsubgpos.hh
Third Party Advisory
https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc
Patch
https://chromium.googlesource.com/chromium/src/+/e1f324aa681af54101c1f2d173d92adb80e37088/DEPS#361
Patch
https://github.com/harfbuzz/harfbuzz/blob/2822b589bc837fae6f66233e2cf2eef0f6ce8470/src/hb-ot-layout-gsubgpos.hh
Third Party Advisory
https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc
Patch
Analysis
#
Affected Component
Analysis
harfbuzz
Patched
Vulnerability Ratings
#
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
harfbuzz
buildroot
2025.02.x
10.3.0
Not Affected
harfbuzz
buildroot
master
14.2.1
Not Affected
harfbuzz
yocto
master
14.2.1
Not Affected
harfbuzz
yocto
scarthgap
8.3.0
Not Affected
Resolved with patches
#
harfbuzz (yocto:kirkstone)
#
Title
Author
Resolve
1
[GPOS] Avoid O(n^2) behavior in mark-attachment
Behdad Esfahbod <behdad@behdad.org>
CVE-2023-25193