An integer overflow in the component hb-ot-shape-fallback.cc allows attackers to cause a Denial of Service (DoS) via unspecified vectors. Reference: https://github.com/harfbuzz/harfbuzz/issues/3557 https://github.com/harfbuzz/harfbuzz/commit/62e803b36173fd096d7ad460dd1d1db9be542593
Created harfbuzz tracking bugs for this issue: Affects: fedora-all [bug 2102610] Created mingw-harfbuzz tracking bugs for this issue: Affects: fedora-all [bug 2102611]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2022:8384 https://access.redhat.com/errata/RHSA-2022:8384
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-33068