rootpwn

medium · CVSS v3 5.5 · EPSS 0.00172

CVE-2026-95512

FreeType's CID font loader has a flaw that can be triggered by a specially crafted CID-keyed font. The flaw causes repeated allocations and

Overview

FreeType's CID font loader has a flaw that can be triggered by a specially crafted CID-keyed font. The flaw causes repeated allocations and decryptions, leading to high memory and CPU usage. This can result in a denial of service for applications that render such fonts.

Description

A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.

Impact

The vulnerability leads to denial of service by exhausting memory and CPU resources. It primarily impacts availability, not confidentiality or integrity. Users of applications that render fonts using FreeType—such as web browsers, PDF viewers, and desktop publishing tools—may experience hangs or crashes.

Remediation

Apply the latest FreeType update that fixes the CID font loader bug. If patching is not immediately possible, disable or restrict font rendering for untrusted content, or configure applications to use safer font rendering libraries. Monitor system resources for abnormal spikes when processing fonts.

Risk context

The CVE has a medium severity score (5.5) and a very low EPSS of 0.00172, indicating a low likelihood of exploitation in the wild. Nonetheless, environments that process user-supplied fonts should patch promptly to avoid potential DoS.

Affected products

  • FreeType
  • Linux
  • Ubuntu
  • Fedora
  • Debian
  • Android
  • iOS
  • Adobe Reader

Scores

Severity
medium
CVSS v2
4.9
CVSS v3
5.5
CVSS v4
—
EPSS
0.00172

DoS Memory CPU Font FreeType CID Denial of Service Medium

← All CVEs