CVE-2026-23865Disclosure(freetype / freetype)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch freetype freetype systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freetype

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-02); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
freetype

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-02: 2Mentions · 2026-03-03: 1Mentions · 2026-03-06: 1Mentions · 2026-03-08: 1Mentions · 2026-03-13: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-13: 103-0203-0303-0603-0803-13
Signal classification1 categories
Disclosure
6100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-022
Disclosure2
2026-03-031
Disclosure1
2026-03-061
Disclosure1
2026-03-081
Disclosure1
2026-03-131
Disclosure1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-23865: FreeType: Out of bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts https://www.openwall.com/lists/oss-security/2026/03/03/8 Fixed in 2.14.2

    Post summary

    The text reports CVE‑2026‑23865, an out‑of‑bounds read flaw in FreeType’s variable‑font table parsing, and notes the vulnerability is fixed in version 2.14.2.

    04119146.1K
    4.4K followersView on X
  • Hephaestvs@Vulcanux_
    Disclosure

    csirt_it: Rilevata una nuova vulnerabilità, tracciata tramite la CVE-2026-23865, che interessa la libreria di rendering dei font #FreeType Rischio: 🟡 Tipologia: 🔸 Information Disclosure 🔸 Denial of Service 🔗 https://www.acn.gov.it/portale/w/rilevata-nuova-vulnerabilita-in-freetype ⚠ Importante … https://t.co/wHZDVyhGpa

    Post summary

    The post announces a newly discovered vulnerability (CVE-2026-23865) affecting the FreeType rendering library, noting information disclosure and denial‑of‑service risks without providing exploit details or mitigation.

    0001038
    610 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Critical FreeType flaw in #Ubuntu (USN-8086-1). CVE-2026-23865 is an integer arithmetic issue that can leak sensitive memory. Read more: 👉 https://tinyurl.com/583apfjp #Security https://t.co/dxRTO8usJ9

    Post summary

    The tweet announces that CVE‑2026‑23865 is a critical integer arithmetic flaw in FreeType that can leak memory, and refers to Ubuntu USN‑8086‑1 for a fix.

    0000055
    1.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23865 Integer Overflow in Freetype Library 2.13.2 and 2.13.3 Enables Bounds Read Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23865

    Post summary

    A new integer overflow vulnerability in Freetype Library 2.13.2 and 2.13.3 has been disclosed, allowing a bounds read exploit.

    0000051
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-23865 An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operati… https://www.cve.org/CVERecord?id=CVE-2026-23865 ----- Traducción: CVE-2026-23865 Un … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-23865, detailing an integer overflow in Freetype that could lead to an out‑of‑bounds read, but offers no PoC, exploit, or patch information.

    0000031
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23865 An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operati… https://www.cve.org/CVERecord?id=CVE-2026-23865

    Post summary

    The text announces CVE-2026-23865, an integer overflow in Freetype's tt_var_load_item_variation_store that could lead to out‑of‑bounds reads in versions 2.13.2 and 2.13.3.

    00000201
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreetypefreetype---

Explore more