Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-78518.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-78518
Upstream
Published
2026-03-02T17:16:32Z
Modified
2026-09-16T06:39:01Z
Summary
CVE-2026-23865 affecting package freetype for versions less than 2.13.2-2
Details

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

References

Affected packages

Azure Linux:3 / freetype

Package

Name
freetype
Purl
pkg:rpm/azure-linux/freetype

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.13.2-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-78518.json"