EIP-2026-115637
PRE-CVEMicrosoft DirectWrite / AFDKO - Use of Uninitialized Memory While Freeing Resources in var_loadavar
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-115637. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit targets a memory corruption vulnerability in AFDKO's handling of the 'avar' table in OpenType variable fonts. The PoC triggers a crash by manipulating axisCount and positionMapCount values, leading to uninitialized memory access during cleanup.
Description
Microsoft DirectWrite / AFDKO - Use of Uninitialized Memory While Freeing Resources in var_loadavar
Exploits (1)
This exploit targets a memory corruption vulnerability in AFDKO's handling of the 'avar' table in OpenType variable fonts. The PoC triggers a crash by manipulating axisCount and positionMapCount values, leading to uninitialized memory access during cleanup.