Bug 2460423 (CVE-2026-49919)
| Summary: | CVE-2026-49919 freetype: Integer overflow in FreeType tt_face_colr_blend_layer() leads to heap buffer overflow during COLR font rendering | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | ahughes, caswilli, fferrari, gotiwari, jgrulich, jhorak, kaycoth, khosford, kshier, mtorre, mvyas, pjindal, rhel-process-autobot, security-response-team, stcannon, teagle, tfitzsim, tpopela, watson-tool-maintainers, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in FreeType. An attacker could cause an application crash leading to a Denial of Service (DoS) by tricking a user or application into rendering a specially crafted color font. This issue occurs due to an integer overflow during bitmap dimension calculations when blending color font layers, resulting in an undersized memory allocation. FreeType subsequently performs an out-of-bounds write to heap memory, corrupting process memory.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2545196, 2545197, 2545198, 2545199, 2545200, 2545201, 2545202, 2545203, 2545204, 2545205, 2545206, 2545207, 2545208, 2545209 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-04-21 23:19:37 UTC
Tracker filed for rhel-10.3: https://issues.redhat.com/browse/RHEL-189210 |