Medium severity5.9NVD Advisory· Published Mar 25, 2026· Updated May 12, 2026
CVE-2026-34085
CVE-2026-34085
Description
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
Affected products
1- fontconfig project/fontconfigv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.