https://seclists.org/oss-sec/2026/q1/253: Announcing FeType 2.14.2, fixes CVE-2026-23865
Published Mar 3, 2026
·Updated
Affected Software
1 affected component
FreeType FreeType>=2.13.2<2.13.3, >=2.14.0<2.14.1
Frequently Asked Questions
1
What is the severity of CVE-2026-23865?
CVE-2026-23865 has been classified with a severity rating that indicates a potential risk of integer overflow vulnerabilities.
2
How do I fix CVE-2026-23865?
To fix CVE-2026-23865, update your FreeType library to version 2.14.2 or later.
3
What versions are affected by CVE-2026-23865?
CVE-2026-23865 affects FreeType versions 2.13.2 and 2.13.3.
4
What type of vulnerability is CVE-2026-23865?
CVE-2026-23865 is categorized as an integer overflow vulnerability in the FreeType library.
5
Who should be concerned about CVE-2026-23865?
All users of the FreeType library should be concerned and update to the latest version to mitigate the risk.