EIP-2026-103508
PRE-CVEGraphite2 - NameTable::getName Multiple Heap Out-of-Bounds Reads
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103508. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates multiple memory corruption vulnerabilities (SEGV, heap-buffer-overflow) in Graphite2's NameTable::getName method, triggered by malformed font files. The crashes occur due to improper bounds checking during font parsing, leading to out-of-bounds memory access.
Description
Graphite2 - NameTable::getName Multiple Heap Out-of-Bounds Reads
Exploits (1)
This exploit demonstrates multiple memory corruption vulnerabilities (SEGV, heap-buffer-overflow) in Graphite2's NameTable::getName method, triggered by malformed font files. The crashes occur due to improper bounds checking during font parsing, leading to out-of-bounds memory access.