https://seclists.org/oss-sec/2025/q1/215: CVE-2025-27363: out of bounds write in FeType <= 2.13.0
Published Mar 13, 2025
·Updated
Affected Software
1 affected component
FreeType FreeType<=2.13.0
Frequently Asked Questions
1
What is the severity of CVE-2025-27363?
CVE-2025-27363 has been classified as a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2025-27363?
To mitigate CVE-2025-27363, you should upgrade FreeType to version 2.13.1 or later immediately.
3
What causes CVE-2025-27363?
CVE-2025-27363 is caused by an out of bounds write when parsing font subglyph structures in FreeType versions 2.13.0 and below.
4
Which versions of FreeType are affected by CVE-2025-27363?
CVE-2025-27363 affects FreeType versions up to and including 2.13.0.
5
What types of files are vulnerable in CVE-2025-27363?
CVE-2025-27363 specifically affects TrueType GX and variable font files when processed by FreeType.