CVE-2026-34085

Name
CVE-2026-34085
Description
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://gitlab.freedesktop.org/fontconfig/fontconfig/-/commit/b9bec06d73340f1b5727302d13ac3df307b7febc
cve@mitre.org https://gitlab.freedesktop.org/fontconfig/fontconfig/-/merge_requests/446
cve@mitre.org https://gitlab.freedesktop.org/fontconfig/fontconfig/-/work_items/481

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:fontconfig_project:fontconfig:*:*:*:*:*:*:*:* fontconfig >= None < 2.17.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
fontconfig edge-main 2.15.0-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
fontconfig edge-main 2.15.0-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
fontconfig edge-main 2.15.0-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
fontconfig edge-main 2.15.0-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
fontconfig edge-main 2.15.0-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
fontconfig 3.22-main 2.15.0-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
fontconfig 3.21-main 2.15.0-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
fontconfig 3.20-main 2.15.0-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
fontconfig 3.19-main 2.14.2-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable