CVE-2026-34085Disclosure(fontconfig_project / fontconfig)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch fontconfig_project fontconfig systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-193

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fontconfig

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-25); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Products
fontconfig

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-29: 2Patch / Workaround · 2026-03-29: 2Technical Details · 2026-03-25: 2Technical Details · 2026-03-29: 203-2503-29
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-252
Disclosure2
2026-03-292
Disclosure1Patch1
Full discourse4 posts
  • White Rabbitx@TheRabbitPy
    Patch

    📄 CVE-2026-34085 (fontconfig <2.17.1): 7.8 OOB write in sfnt handling (fcfreetype.c)—crash/code exec. Update now! https://nvd.nist.gov/vuln/detail/CVE-2026-34085

    Post summary

    The post announces a fontconfig vulnerability (CVE‑2026‑34085) that allows out‑of‑bounds write and code execution, and urges users to apply the available update immediately.

    1000055
    492 followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    ⚠️ CVE-2026-34085 (fontconfig <2.17.1): High 7.8 off-by-one OOB write in sfnt handling—crash or code exec. Update immediately! https://nvd.nist.gov/vuln/detail/CVE-2026-34085

    Post summary

    This post warns of CVE-2026-34085, a high‑severity off‑by‑one out‑of‑bounds write in fontconfig that could cause crashes or code execution, and urges users to apply the available update.

    1000035
    492 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34085 FontConfig Heap Overflow Vulnerability in Font Capability Handling Before 2.17.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34085

    Post summary

    The post announces a heap overflow vulnerability in FontConfig (CVE-2026-34085) affecting versions prior to 2.17.1, but does not provide PoC, exploit code, patch, or active exploitation details.

    0001041
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34085 fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or … https://www.cve.org/CVERecord?id=CVE-2026-34085

    Post summary

    The post announces an off‑by‑one memory overrun in fontconfig 2.17.1 that could cause crashes, with no active exploitation or mitigation details provided.

    00000132
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfontconfig_projectfontconfig2.17.0--

Explore more