Bug 2454161 (CVE-2026-5314)

Summary: CVE-2026-5314 Nothings stb: stb_truetype.h: Nothings stb: Denial of Service via out-of-bounds read in stb_truetype.h
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Nothings stb, specifically within the stbtt_InitFont_internal function in the stb_truetype.h library. A remote attacker can exploit this vulnerability by performing a manipulation that leads to an out-of-bounds read. This can result in a Denial of Service (DoS), making the affected component unavailable. The exploit for this vulnerability has been publicly disclosed.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2454220    
Bug Blocks:    

Description OSIDB Bzimport 2026-04-01 23:01:51 UTC
A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.