CVE-2026-5315: Nothings stb TTF File stb_truetype.h stbtt__buf_get8 out-of-bounds
A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbttbufget8 in the library stbtruetype.h of the component TTF File Handler. Executing a manipulation can lead to out-of-bounds read. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5315?
CVE-2026-5315 has a high severity due to the risk of out-of-bounds reading that could lead to information disclosure.
How do I fix CVE-2026-5315?
To fix CVE-2026-5315, update the Nothings stb_truetype.h library to version 1.27 or later.
What type of vulnerability is CVE-2026-5315?
CVE-2026-5315 is an out-of-bounds read vulnerability found in the function stbtt__buf_get8.
Which versions of stb_truetype.h are affected by CVE-2026-5315?
CVE-2026-5315 affects versions of Nothings stb_truetype.h up to and including version 1.26.
What can be exploited via CVE-2026-5315?
Exploitation of CVE-2026-5315 can lead to unauthorized information disclosure through out-of-bounds read vulnerabilities.