Denial of Service Vulnerability in FreeType CID Font Loader
CVE-2026-95512
5.5MEDIUM
What is CVE-2026-95512?
FreeType contains a vulnerability in its CID font loader, enabling remote attackers to exploit the flaw by persuading users to open content that embeds or references a specially crafted CID-keyed font. This type of font can initiate repeated allocations and decryptions of subroutine data across several font dictionaries, ultimately consuming excessive memory and processing power. This may lead to a denial of service for applications or services handling the font, causing them to become unresponsive or crash.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.