RHSA-2025:8292: Important: mingw-freetype and spice-client-win security update
Published May 29, 2025
·Updated
Important: mingw-freetype and spice-client-win security update
Affected Software
15 affected componentsFixes available
Red Hat Red Hat Enterprise Linux for x86_64
Red Hat Red Hat Enterprise Linux for ARM 64
Red Hat Red Hat Enterprise Linux for Power, little endian
Red Hat Red Hat Enterprise Linux for IBM z Systems
Red Hat Red Hat CodeReady Linux Builder for x86_64
redhat/spice-client-win<8.10-1.el8_10
8.10-1.el8_10
redhat/spice-client-win-x64<8.10-1.el8_10
8.10-1.el8_10
redhat/spice-client-win-x86<8.10-1.el8_10
8.10-1.el8_10
redhat/mingw-freetype<2.8-3.el8_10.1
2.8-3.el8_10.1
redhat/mingw32-freetype<2.8-3.el8_10.1
2.8-3.el8_10.1
redhat/mingw32-freetype-debuginfo<2.8-3.el8_10.1
2.8-3.el8_10.1
redhat/mingw32-freetype-static<2.8-3.el8_10.1
2.8-3.el8_10.1
redhat/mingw64-freetype<2.8-3.el8_10.1
2.8-3.el8_10.1
redhat/mingw64-freetype-debuginfo<2.8-3.el8_10.1
2.8-3.el8_10.1
redhat/mingw64-freetype-static<2.8-3.el8_10.1
2.8-3.el8_10.1
Remediation
Event History
May 29, 2025
Advisory Published
via Red Hat·06:15 AM
Frequently Asked Questions
1
What is the severity of RHSA-2025:8292?
The severity of RHSA-2025:8292 is classified as important.
2
How do I fix RHSA-2025:8292?
To fix RHSA-2025:8292, update the affected packages to the specified versions provided in the advisory.
3
What vulnerabilities are addressed in RHSA-2025:8292?
RHSA-2025:8292 addresses vulnerabilities including an out-of-bounds write in freetype related to TrueType GX and variable font files (CVE-2025-27363).
4
What packages are affected by RHSA-2025:8292?
Affected packages include spice-client-win, mingw-freetype, and their associated versions.
5
Is service downtime required for RHSA-2025:8292 remediation?
Service downtime is not typically required to apply the updates for RHSA-2025:8292, but it is recommended to perform the update during scheduled maintenance.