Bug 2531287 - CVE-2026-79515 stb: stb: Denial of Service via crafted TTF file [fedora-all]
Summary: CVE-2026-79515 stb: stb: Denial of Service via crafted TTF file [fedora-all]
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: stb
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Ben Beasley
QA Contact:
URL:
Whiteboard: {"flaws": ["5cecea2a-4228-4b95-9f8f-4...
Depends On:
Blocks: CVE-2026-79515
TreeView+ depends on / blocked
 
Reported: 2026-09-10 06:26 UTC by Vladimir Vasilev
Modified: 2026-09-10 07:41 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-09-10 07:41:43 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Vladimir Vasilev 2026-09-10 06:26:51 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.

Comment 1 Ben Beasley 2026-09-10 07:41:43 UTC
Neither the CVE https://www.cve.org/CVERecord?id=CVE-2026-79515 nor the linked upstream issue https://github.com/nothings/stb/issues/1962 includes a patch.

Given that the stb_truetype library begins with the following prominent warning,

// =======================================================================
//
//    NO SECURITY GUARANTEE -- DO NOT USE THIS ON UNTRUSTED FONT FILES
//
// This library does no range checking of the offsets found in the file,
// meaning an attacker can use it to read arbitrary memory.
//
// =======================================================================

it’s certain that upstream would not consider this a valid bug.

For those reasons, I’m not interested in trying to develop a patch for this, either.

Given that there’s no patch and probably never will be one, it doesn’t seem useful to track this downstream.

Feel free to reopen this or open a PR if a proposed patch appears, but please understand that stb_truetype is expected to be absolutely riddled with problems like this when used outside of the applications for which it was designed.


Note You need to log in before you can comment on or make changes to this bug.