VYPR
Medium severity5.9NVD Advisory· Published Mar 25, 2026· Updated May 12, 2026

CVE-2026-34085

CVE-2026-34085

Description

fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.

Affected products

1
  • fontconfig project/fontconfigv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.