USN-7251-1: HarfBuzz vulnerability
Published Feb 3, 2025
·Updated
It was discovered that HarfBuzz incorrectly handled shaping certain fonts. A remote attacker could possibly use this issue to cause HarfBuzz to consume resources, leading to a denial of service.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/libharfbuzz0b<2.7.4-1ubuntu3.2
2.7.4-1ubuntu3.2
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libharfbuzz0b<2.6.4-1ubuntu4.3
2.6.4-1ubuntu4.3
Ubuntu Ubuntu=20.04
Event History
Feb 3, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7251-1?
The severity of USN-7251-1 is related to a denial of service risk due to resource consumption by HarfBuzz.
2
How do I fix USN-7251-1?
To fix USN-7251-1, upgrade the libharfbuzz0b package to version 2.7.4-1ubuntu3.2 for Ubuntu 22.04 or to version 2.6.4-1ubuntu4.3 for Ubuntu 20.04.
3
Who is affected by USN-7251-1?
Users of Ubuntu 22.04 and Ubuntu 20.04 running vulnerable versions of libharfbuzz0b are affected by USN-7251-1.
4
What products are impacted by USN-7251-1?
The impacted products are libharfbuzz0b on Ubuntu 22.04 and Ubuntu 20.04.
5
What type of issue is reported in USN-7251-1?
USN-7251-1 reports a denial of service vulnerability due to improper handling of certain fonts by HarfBuzz.