VDB

TNCVE-2026-23865

TNCVE-2026-23865 PUBLISHED

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

Timeline

  • Mar 2, 2026 CVE Published

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›