CVE-2022-27406: High severity FreeType vulnerability
FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FTRequestSize.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/freetypeto a version that resolves this vulnerability.Fixed in 2.12.0 - Upgrade
Upgrade
debian/freetypeto a version that resolves this vulnerability.Fixed in 2.10.4+dfsg-1+deb11u1Fixed in 2.10.4+dfsg-1+deb11u2Fixed in 2.12.1+dfsg-5+deb12u3Fixed in 2.12.1+dfsg-5+deb12u4Fixed in 2.13.3+dfsg-1
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27406?
The severity of CVE-2022-27406 is high, with a CVSS score of 7.5.
How does CVE-2022-27406 affect FreeType and Fedora?
CVE-2022-27406 affects FreeType versions up to 2.12.0 and Fedora versions 34, 35, and 36.
What is the vulnerability in CVE-2022-27406?
The vulnerability in CVE-2022-27406 is a segmentation violation in the function FT_Request_Size of FreeType.
Where can I find more information about CVE-2022-27406?
You can find more information about CVE-2022-27406 at the following references: http://freetype.com, https://gitlab.freedesktop.org/freetype/freetype/-/issues/1140, https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EFPNRKDLCXHZVYYQLQMP44UHLU32GA6Z/
Is there a fix available for CVE-2022-27406?
Yes, a fix for CVE-2022-27406 is available. Please refer to the relevant vendor or project for the fix details.