CVE-2024-56732Patch(harfbuzz_project / harfbuzz)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch harfbuzz_project harfbuzz systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • harfbuzz

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
harfbuzz

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-25: 1Patch / Workaround · 2026-06-25: 1Technical Details · 2026-06-25: 106-25
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2024-56732 - HarfBuzz text shaping engine heap buffer overflow (CVSS 8.8). Affects versions 8.5.0-10.0.1. Remote exploitation possible with user interaction. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/k6k0qLWiBO

    Post summary

    The tweet announces CVE‑2024‑56732, a heap buffer overflow in HarfBuzz, highlights remote exploitability with user interaction, and urges immediate patching.

    0000039
    52 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appharfbuzz_projectharfbuzz---

Explore more