CVE-2026-23865

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*
cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-02 17:16

Updated : 2026-06-17 10:22


NVD link : CVE-2026-23865

Mitre link : CVE-2026-23865

CVE.ORG link : CVE-2026-23865


JSON object : View

Products Affected

freetype

  • freetype
CWE
CWE-125

Out-of-bounds Read