https://seclists.org/oss-sec/2026/q1/49: Null Pointer Defence in HarfBuzz
Published Jan 11, 2026
·Updated
Affected Software
1 affected component
HarfBuzz HarfBuzz<12.3.0
Frequently Asked Questions
1
What is the severity of GHSA-xvjr-f2r9-c7ww?
The severity of GHSA-xvjr-f2r9-c7ww is classified as high due to the potential for null pointer dereference leading to application crashes.
2
How do I fix GHSA-xvjr-f2r9-c7ww?
To fix GHSA-xvjr-f2r9-c7ww, upgrade HarfBuzz to version 12.3.1 or later.
3
Which versions of HarfBuzz are affected by GHSA-xvjr-f2r9-c7ww?
HarfBuzz version 12.3.0 and earlier versions are affected by GHSA-xvjr-f2r9-c7ww.
4
What type of vulnerability is GHSA-xvjr-f2r9-c7ww?
GHSA-xvjr-f2r9-c7ww is a null pointer dereference vulnerability.
5
What is the impact of the vulnerability GHSA-xvjr-f2r9-c7ww?
The impact of GHSA-xvjr-f2r9-c7ww may result in application crashes or denial of service.