{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: out-of-bounds write when parsing composite subglyphs\n     of TrueType GX / variable fonts (ELSCVE-171535)\n     - debian/patches-freetype/CVE-2025-27363.patch: reject a subglyph count\n       that truncates to a negative short in load_truetype_glyph before it\n       is used to size the outline arrays in src/truetype/ttgload.c.\n     - CVE-2025-27363",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787310855",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787310855"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu18.04els/advisories/2026/clsa-2026_1787310855.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-21T11:14:51Z",
      "generator": {
        "date": "2026-08-21T11:14:51Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1787310855",
      "initial_release_date": "2026-08-21T11:14:51Z",
      "revision_history": [
        {
          "date": "2026-08-21T11:14:51Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix CVE(s): CVE-2025-27363"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 18.04",
                "product": {
                  "name": "Ubuntu 18.04",
                  "product_id": "Ubuntu-18",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "freetype2-demos-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
                "product": {
                  "name": "freetype2-demos-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
                  "product_id": "freetype2-demos-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/freetype2-demos@2.8.1-2ubuntu2.2%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libfreetype6-dev-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
                "product": {
                  "name": "libfreetype6-dev-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
                  "product_id": "libfreetype6-dev-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libfreetype6-dev@2.8.1-2ubuntu2.2%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libfreetype6-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
                "product": {
                  "name": "libfreetype6-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
                  "product_id": "libfreetype6-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libfreetype6@2.8.1-2ubuntu2.2%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "freetype2-demos-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:freetype2-demos-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64"
        },
        "product_reference": "freetype2-demos-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libfreetype6-dev-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libfreetype6-dev-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64"
        },
        "product_reference": "libfreetype6-dev-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libfreetype6-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libfreetype6-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64"
        },
        "product_reference": "libfreetype6-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-27363",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-18:freetype2-demos-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
          "Ubuntu-18:libfreetype6-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
          "Ubuntu-18:libfreetype6-dev-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-27363"
        },
        {
          "category": "external",
          "summary": "https://www.facebook.com/security/advisories/cve-2025-27363",
          "url": "https://www.facebook.com/security/advisories/cve-2025-27363"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/03/13/1",
          "url": "http://www.openwall.com/lists/oss-security/2025/03/13/1"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/03/13/11",
          "url": "http://www.openwall.com/lists/oss-security/2025/03/13/11"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/03/13/12",
          "url": "http://www.openwall.com/lists/oss-security/2025/03/13/12"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/03/13/2",
          "url": "http://www.openwall.com/lists/oss-security/2025/03/13/2"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/03/13/3",
          "url": "http://www.openwall.com/lists/oss-security/2025/03/13/3"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/03/13/8",
          "url": "http://www.openwall.com/lists/oss-security/2025/03/13/8"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/03/14/1",
          "url": "http://www.openwall.com/lists/oss-security/2025/03/14/1"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/03/14/2",
          "url": "http://www.openwall.com/lists/oss-security/2025/03/14/2"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/03/14/3",
          "url": "http://www.openwall.com/lists/oss-security/2025/03/14/3"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/03/14/4",
          "url": "http://www.openwall.com/lists/oss-security/2025/03/14/4"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/05/06/3",
          "url": "http://www.openwall.com/lists/oss-security/2025/05/06/3"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/16/5",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/16/5"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/19/3",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/19/3"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/03/msg00030.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00030.html"
        },
        {
          "category": "external",
          "summary": "https://source.android.com/docs/security/bulletin/2025-05-01",
          "url": "https://source.android.com/docs/security/bulletin/2025-05-01"
        },
        {
          "category": "external",
          "summary": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27363",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27363"
        }
      ],
      "release_date": "2025-03-11T14:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-21T11:14:17.800849Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787310855",
          "product_ids": [
            "Ubuntu-18:freetype2-demos-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
            "Ubuntu-18:libfreetype6-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64",
            "Ubuntu-18:libfreetype6-dev-0:2.8.1-2ubuntu2.2+tuxcare.els1.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787310855"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}