Release date:
2026-08-21 11:14:26 UTC
Description:
* SECURITY UPDATE: out-of-bounds write when parsing composite subglyphs
of TrueType GX / variable fonts (ELSCVE-171535)
- debian/patches-freetype/CVE-2025-27363.patch: reject a subglyph count
that truncates to a negative short in load_truetype_glyph before it
is used to size the outline arrays in src/truetype/ttgload.c.
- CVE-2025-27363
Updated packages:
-
freetype2-demos_2.8.1-2ubuntu2.2+tuxcare.els1_amd64.deb
sha:857abc48a861331dd4bd512751ac5160b2ee294c
-
libfreetype6_2.8.1-2ubuntu2.2+tuxcare.els1_amd64.deb
sha:75cb7613afc54b2c1d3e67d2484152232270ec9b
-
libfreetype6-dev_2.8.1-2ubuntu2.2+tuxcare.els1_amd64.deb
sha:b957d721cb472865341dd1c7589a10777dd64a2c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.