Medium severity6.5OSV Advisory· Published Jul 7, 2026· Updated Jul 9, 2026
CVE-2026-50811
CVE-2026-50811
Description
An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates
Affected products
5- osv-coords3 versionspkg:rpm/opensuse/freetype2&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/freetype2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ft2demos&distro=openSUSE%20Leap%2016.0
< 2.14.3-160000.1.1+ 2 more
- (no CPE)range: < 2.14.3-160000.1.1
- (no CPE)range: < 2.14.3-1.1
- (no CPE)range: < 2.14.3-160000.1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.