#1149953 freetype: CVE-2026-95512

Package:
src:freetype
Source:
src:freetype
Submitter:
Salvatore Bonaccorso
Date:
2026-10-05 11:39:03 UTC
Severity:
normal
Tags:
#1149953#5
Date:
2026-10-04 18:46:51 UTC
From:
To:
Hi,

The following vulnerability was published for freetype.

CVE-2026-95512[0]:
| A flaw was found in FreeType, specifically within its CID font
| loader. A remote attacker could exploit this vulnerability by
| tricking a user into opening content that embeds or references a
| specially crafted CID-keyed font. This crafted font can cause
| repeated allocations and decryptions of subroutine data across
| multiple font dictionaries, leading to excessive memory and CPU
| consumption. This can result in a denial of service (DoS) for the
| application or service processing the font, potentially causing it
| to hang or terminate.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-95512
https://www.cve.org/CVERecord?id=CVE-2026-95512
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2462295
[2] https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149953#8
Date:
2026-10-05 11:20:32 UTC
From:
To:
Hello,

Bug #1149953 in freetype reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/debian/freetype/-/commit/bb2bd4b4685d62344f73d6613efddd10f7153734
------------------------------------------------------------------------
debian/patches: Fix CVE-2026-95512

Prevent denial of service via repeated subroutine allocations in
the CID font loader.

Crafted CID fonts can trigger repeated subroutine allocations and
decryptions across many font dictionaries during face loading,
causing severe memory and CPU exhaustion.

Closes: #1149953
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149953

#1149953#15
Date:
2026-10-05 11:36:29 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
freetype, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1149953@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Hugh McMaster <hmc@debian.org> (supplier of updated freetype package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 05 Oct 2026 22:05:47 +1100
Source: freetype
Architecture: source
Version: 2.14.3+dfsg-3
Distribution: unstable
Urgency: medium
Maintainer: Hugh McMaster <hmc@debian.org>
Changed-By: Hugh McMaster <hmc@debian.org>
Closes: 1149953
Changes:
 freetype (2.14.3+dfsg-3) unstable; urgency=medium
 .
   * debian/patches: Fix CVE-2026-95512 (Closes: #1149953).
Checksums-Sha1:
 3b53503b66d6dc1d7deddd65bdb42c4d796f79c4 4011 freetype_2.14.3+dfsg-3.dsc
 d97fb4f9b54f75581cc22a33718acd56f9f1c24f 45428 freetype_2.14.3+dfsg-3.debian.tar.xz
 164edb76ff8fb6a37a50755d47f34cfc2a9c0d87 6382 freetype_2.14.3+dfsg-3_source.buildinfo
Checksums-Sha256:
 7cf37005c2db2768b8246508ad484338c0a9910b31ab6dc45a2078ebd7c84f50 4011 freetype_2.14.3+dfsg-3.dsc
 3f0e24e23973f3b51a579ccac9b2612f41f871df23853267bd967bf8de66dd60 45428 freetype_2.14.3+dfsg-3.debian.tar.xz
 b7c0e1e423b64a4c5ce1c73afc6c85c6eaa24fb24bb1a54d87132e03d486f3d8 6382 freetype_2.14.3+dfsg-3_source.buildinfo
Files:
 2ff2dd4210b7cdf80dce940fc37984d3 4011 libs optional freetype_2.14.3+dfsg-3.dsc
 6675c941ce165ccd8edfc443e964ce5d 45428 libs optional freetype_2.14.3+dfsg-3.debian.tar.xz
 d69afd464435424ac832393851779167 6382 libs optional freetype_2.14.3+dfsg-3_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJDBAEBCgAtFiEEOiCBPKV5RoaMUVIRWsYQdMXoG8QFAmrDh5sPHGhtY0BkZWJp
YW4ub3JnAAoJEFrGEHTF6BvEh4AQAK7JGN3v4taURdgHbRIjP+d82Gu5onAruZUX
MME4cZUiP8vRF6Z/ylluMR2WJWiOhMkOflT3jJZfZcOp/k1mDQY9aaxYEBuAeHxp
Ss9sJ1a0+bKqXTsj4ltUKUkBVQkyZCYpzITo23ysySgJXZXARg7pWdNfVNlq8cGS
ehV2wAPeSlk3XEv1LbrSd9jIE2lf+uGGowqBMoecpasd3JnYZiIzUyk/iQIbB8hM
8ljgwXBShWleXTzlgMSgB6Wf+tqfRJ14onzBSOAuN0K7GRBrF/XNHpjFmz00bQrD
qmqrHawjW4fhnVkdM++VVmt97f3b8mWrjnejb/Xr/HQ6fWPKd8jcmgL8VWp9aBdI
zZV4yqZpFvfeX1WsU4xIzENedMS8CdWvxjR0j1kcEajK+kpwMA1Q6dKs1zM4+SqN
bAJ7aehKpI2ZufmTw7tGgHcTRkQ6ow3xtxElvt4XN9K/BsTnaD1jX0JH/rQV3Xph
mKfEGRymrEvjyZREocEBSHloHGwzuwoundbh7OMalpexIIyhZtlmnK/0ud+ox5kl
60kfPnNRStNcjvfEj18AA8sV0tqRBhzcR/tyMPBfuKPHM0VY0BHioqXB1a18m+PD
JzDAZ444lXlZjS9h3r8WYKlMKJoCt3SUilT/XVYEAnjkUbcX3Ewf+S5XXQA6SLdk
uZJb4Q5D
=l+nf
-----END PGP SIGNATURE-----