medium · CVSS v3 5.5 · EPSS 0.00172
CVE-2026-95512
FreeType's CID font loader has a flaw that can be triggered by a specially crafted CID-keyed font. The flaw causes repeated allocations and
Overview
FreeType's CID font loader has a flaw that can be triggered by a specially crafted CID-keyed font. The flaw causes repeated allocations and decryptions, leading to high memory and CPU usage. This can result in a denial of service for applications that render such fonts.
Description
A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.
Impact
The vulnerability leads to denial of service by exhausting memory and CPU resources. It primarily impacts availability, not confidentiality or integrity. Users of applications that render fonts using FreeType—such as web browsers, PDF viewers, and desktop publishing tools—may experience hangs or crashes.
Remediation
Apply the latest FreeType update that fixes the CID font loader bug. If patching is not immediately possible, disable or restrict font rendering for untrusted content, or configure applications to use safer font rendering libraries. Monitor system resources for abnormal spikes when processing fonts.
Risk context
The CVE has a medium severity score (5.5) and a very low EPSS of 0.00172, indicating a low likelihood of exploitation in the wild. Nonetheless, environments that process user-supplied fonts should patch promptly to avoid potential DoS.
Affected products
- FreeType
- Linux
- Ubuntu
- Fedora
- Debian
- Android
- iOS
- Adobe Reader
Scores
- Severity
- medium
- CVSS v2
- 4.9
- CVSS v3
- 5.5
- CVSS v4
- —
- EPSS
- 0.00172