CVE-2026-95512

⚪ Do wiadomości

Błąd w FreeType umożliwia zdalnemu atakującemu wywołanie odmowy usługi przez specjalnie przygotowany font.

CVSS
5.5
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-10-02 09:16:45 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:44:11 UTC
Referencje