Denial of Service Vulnerability in FreeType CID Font Loader
CVE-2026-95512

5.5MEDIUM

What is CVE-2026-95512?

FreeType contains a vulnerability in its CID font loader, enabling remote attackers to exploit the flaw by persuading users to open content that embeds or references a specially crafted CID-keyed font. This type of font can initiate repeated allocations and decryptions of subroutine data across several font dictionaries, ultimately consuming excessive memory and processing power. This may lead to a denial of service for applications or services handling the font, causing them to become unresponsive or crash.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.