CVE-2026-34085: High severity Fontconfig fontconfig vulnerability
Published Mar 25, 2026
·Updated
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
Affected Software
2 affected components
Fontconfig fontconfig<2.17.1
Fontconfig Project Fontconfig=2.17.0
Remediation
Event History
Mar 25, 2026
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34085?
CVE-2026-34085 is categorized as a high severity vulnerability due to its potential for code execution and system crashes.
2
How do I fix CVE-2026-34085?
To fix CVE-2026-34085, upgrade Fontconfig to version 2.17.1 or later.
3
What causes the vulnerability CVE-2026-34085?
CVE-2026-34085 is caused by an off-by-one error in memory allocation during sfnt capability handling in Fontconfig.
4
Which versions of Fontconfig are affected by CVE-2026-34085?
Fontconfig versions prior to 2.17.1 are affected by CVE-2026-34085.
5
What are the risks associated with CVE-2026-34085?
The risks associated with CVE-2026-34085 include potential crashes and arbitrary code execution on affected systems.