[CLSA-2026:1787310855] Fix CVE(s): CVE-2025-27363
Type:
security
Severity:
Important
Release date:
2026-08-21 11:14:26 UTC
Description:
* SECURITY UPDATE: out-of-bounds write when parsing composite subglyphs of TrueType GX / variable fonts (ELSCVE-171535) - debian/patches-freetype/CVE-2025-27363.patch: reject a subglyph count that truncates to a negative short in load_truetype_glyph before it is used to size the outline arrays in src/truetype/ttgload.c. - CVE-2025-27363
CVEs fixed:
Updated packages:
  • freetype2-demos_2.8.1-2ubuntu2.2+tuxcare.els1_amd64.deb
    sha:857abc48a861331dd4bd512751ac5160b2ee294c
  • libfreetype6_2.8.1-2ubuntu2.2+tuxcare.els1_amd64.deb
    sha:75cb7613afc54b2c1d3e67d2484152232270ec9b
  • libfreetype6-dev_2.8.1-2ubuntu2.2+tuxcare.els1_amd64.deb
    sha:b957d721cb472865341dd1c7589a10777dd64a2c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.