CVE-2026-95512: Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader

Published Apr 26, 2026
·
Updated

A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.

Other sources

AIONLYREPORT package: freetype-2.13.2-8.el10 ------ Summary: Denial of Service via Overlapping CID Subroutine Maps: crafted CID fonts can trigger repeated subroutine allocations and decryptions across many font dictionaries during face loading, causing severe memory and CPU exhaustion. Requirements to exploit: An attacker must reach a build of freetype-2.13.2-8.el10 that includes the CID loader and cause an application or service to load a crafted CID-keyed font. No privileges are required. In common client-side cases this means getting a user to open content that embeds or references the font. Component affected: freetype-2.13.2-8.el10, CID loader in src/cid/cidload.c (parsefdarray, cidfaceopen, cidreadsubrs) Version affected: freetype-2.13.2-8.el10 Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: None established. CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H - 6.5 (MEDIUM) AV:N - The malicious font can be delivered through remotely supplied content before local parsing. AC:L - The attacker needs only a syntactically valid CID font that reuses the same or overlapping subroutine regions across many dictionaries. PR:N - No authentication or prior access is required. UI:R - The demonstrated path requires the victim application to load attacker-controlled content that causes the font to be parsed. S:U - The impact remains within the same security scope as the parsing process. C:N - No confidentiality impact is established. I:N - No integrity impact is established. A:H - Face initialization can perform large repeated allocations and decryptions, potentially hanging or terminating the process. Impact: Important. Red Hat classifies flaws that allow remote users to cause denial of service as Important when they can readily impact availability. In deployments that expose this CID parsing path to attacker-controlled fonts, a crafted input can drive high memory and CPU consumption and deny service to the parsing process. The issue does not rise to Critical because the available evidence shows availability impact only, and the common exploitation path still requires the crafted font to be loaded. Embargo: no Reason: The currently established impact is denial of service during font loading, with no evidence of code execution, privilege escalation, or data exposure. Operational mitigations are also available while a fix is prepared. Acknowledgement: Aisle Research Vulnerability Details: In the reviewed CID loader code, cidreadsubrs allocates, reads, and decrypts subroutine data independently for each font dictionary. If many dictionaries point at the same or overlapping SubrMapOffset region, the same underlying data can be copied and decrypted repeatedly. c / src/cid/cidload.c: cidreadsubrs / for ( n = 0; n < cid->numdicts; n+, subr+ ) { CIDFaceDict dict = cid->fontdicts + n; FTUInt count, numsubrs = dict->numsubrs; ... datalen = offsets[numsubrs] - offsets[0]; if ( FTQNEWARRAY( subr->code, numsubrs + 1 ) || FTQALLOC( subr->code[0], datalen ) ) goto Fail; if ( FTSTREAMSEEK( cid->dataoffset + offsets[0] ) || FTSTREAMREAD( subr->code[0], datalen ) ) goto Fail; if ( lenIV >= 0 ) for ( count = 0; count < numsubrs; count++ ) psaux->t1decrypt( subr->code[count], len, 4330 ); } The number of dictionaries can scale with the font size, and the validation in the reviewed path is per-dictionary rather than cumulative across the whole face: c / src/cid/cidload.c: parsefdarray / maxdicts = (FTLong)( stream->size / 100 ); if ( numdicts > maxdicts ) { ... numdicts = maxdicts; } / src/cid/cidload.c: cidfaceopen / if ( dict->subrmapoffset > binarylength ) { FTERROR(( "cidfaceopen: Invalid SubrMapOffset' value\n" )); error = FTTHROW( InvalidFileFormat ); goto Exit; } / the initial pre-check prevents the multiplication overflow / if ( dict->numsubrs > FTUINTMAX / 4 || dict->numsubrs dict->sdbytes > binarylength - dict->subrmapoffset ) { FTERROR(( "cidfaceopen: Invalid SubrCount' value\n" )); error = FTTHROW( InvalidFileFormat ); goto Exit; } These checks appear to prevent out-of-bounds access and integer overflow in the reviewed path, but they do not stop cross-dictionary resource amplification. A crafted CID font can therefore cause large repeated allocations, reads, and t1decrypt work during face initialization alone; no glyph rendering is required. Steps to reproduce: 1. Build a CID font with a large FDArray, for example near streamsize / 100 dictionaries. 2. Set many dictionaries to the same SubrMapOffset and the same SubrCount and SDBytes values. 3. Make the shared offset table valid and monotonic, with large datalen = offsets[last] - offsets[0], still bounded by the binary section size. 4. Load the font through the affected package; face initialization is sufficient. 5. Observe repeated allocations, copies, and decryptions for each dictionary; resident memory and CPU usage rise roughly with the number of dictionaries until the process stalls or hits out-of-memory conditions. Mitigation: Until a fix is available, avoid parsing attacker-controlled CID-keyed fonts in processes that cannot tolerate memory or CPU spikes. If untrusted font handling is required, isolate font parsing in a separate process or container and apply strict memory and CPU limits. If deployments can reject CID fonts before they reach FreeType, that removes this trigger path. Proposed Fix: Add cumulative per-face limits in cidreadsubrs so one face load cannot multiply subroutine memory and work across many dictionaries without bound. A stronger follow-up would deduplicate identical subroutine regions across dictionaries. diff diff --git a/src/cid/cidload.c b/src/cid/cidload.c @@ -531,6 +531,12 @@ cidreadsubrs( CIDFace face ) FTUInt maxoffsets = 0; FTULong offsets = NULL; PSAuxService psaux = (PSAuxService)face->psaux; + FTULong totalsubrbytes = 0; + FTULong totalsubrcount = 0; + FTULong binarylen = stream->size - cid->dataoffset; + FTULong maxtotalsubrbytes = + ( binarylen <= FTULONGMAX / 4 ) ? binarylen 4 : FTULONGMAX; + FTULong maxtotalsubrcount = (FTULong)cid->numdicts 65535UL; @@ -599,6 +605,19 @@ cidreadsubrs( CIDFace face ) datalen = offsets[numsubrs] - offsets[0]; + if ( totalsubrbytes > FTULONGMAX - datalen || + totalsubrcount > FTULONGMAX - numsubrs ) + { + error = FTTHROW( InvalidFileFormat ); + goto Fail; + } + totalsubrbytes += datalen; + totalsubrcount += numsubrs; + if ( totalsubrbytes > maxtotalsubrbytes || + totalsubrcount > maxtotalsubrcount ) + { + error = FTTHROW( InvalidFileFormat ); + goto Fail; + } + if ( FTQNEWARRAY( subr->code, numsubrs + 1 ) || FTQALLOC( subr->code[0], datalen ) ) goto Fail; ------ This report was generated using AI technology. Always review AI-generated content prior to use

— Red Hat

Affected Software

2 affected componentsFixes available
redhat/freetype=2.13.2-8.el10
debian/freetype<=2.12.1+dfsg-5+deb12u4, <=2.13.3+dfsg-1+deb13u1, <=2.14.3+dfsg-2
2.14.3+dfsg-3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/freetype to a version that resolves this vulnerability.

    Fixed in 2.14.3+dfsg-3
  2. Compensating control

    Reject CID-keyed fonts before they reach FreeType to remove the repeated-subroutine-allocation trigger.

  3. Compensating control

    Isolate untrusted font parsing in a separate process or container and apply strict memory and CPU limits.

Event History

Apr 26, 2026
Data Sourced
via Red Hat·06:45 PM
DescriptionSeverityAffected Software
Oct 2, 2026
CVE Published
via MITRE·09:05 AM
Data Sourced
via MITRE·09:05 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Oct 6, 2026
Data Sourced
via Ubuntu·02:42 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·02:42 PM
Description
Data Sourced
via Debian·02:42 PM
DescriptionAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203