PT-2026-56283 · Freetype · Freetype

·

CVE-2026-50811

·

Published

2026-07-07

·

Updated

2026-07-31

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions FreeType versions prior to commit 5a280ecde6f324de0d226261036e736e0cb49a71
Description An out-of-bounds read occurs in the TT Get Var Design() implementation, which is utilized by FT Get Var Design Coordinates(). This issue is located within the src/truetype/ttgxvar.c file. An out-of-bounds read is a condition where a program reads data past the end of the intended buffer, potentially leading to information disclosure or system crashes.
Recommendations Update FreeType to the version containing commit 5a280ecde6f324de0d226261036e736e0cb49a71.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50811
ECHO-7AAD-5728-3A60
OPENSUSE-SU-2026:11257-1
OPENSUSE-SU-2026:21362-1
RHSA-2026:36841
SUSE-SU-2026:22750-1
SUSE-SU-2026:22815-1
SUSE-SU-2026:22922-1
SUSE-SU-2026:23074-1
USN-8562-1

Affected Products

Freetype