Description
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
Scores
CVSS v3
5.9
EPSS
0.0001
EPSS Percentile
2.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-193
Status
published
Products (3)
fontconfig/fontconfig
< 2.17.1
fontconfig project/fontconfig
< 2.17.1
fontconfig_project/fontconfig
< 2.17.1
Published
Mar 25, 2026
Tracked Since
Mar 25, 2026