Sceawere

Vulnerability Detail

CVE-2026-95512UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FreeType CID Font DoS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
14h ago
Vendor
Red Hat
Product
Red Hat Hardened Images
Attack Type
Uncontrolled Resource Consumption
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-10-02T09:16:45.300Z",
  "pubdate": "2026-10-02T09:16:45.300Z",
  "executiveSummary": "A resource exhaustion vulnerability exists within the FreeType CID font loader, classified as a Denial of Service (DoS) flaw.\nThe vulnerability manifests when the library processes maliciously crafted CID-keyed fonts, leading to uncontrolled memory allocation and CPU cycles.\nThe flaw affects systems utilizing FreeType for font rendering, potentially impacting a wide range of applications, including web browsers, document viewers, and graphic processing software.\nAn unauthenticated, remote attacker can trigger this vulnerability by enticing a user to open a document or web page containing a specially crafted font.\nSuccessful exploitation results in severe performance degradation or the abrupt termination of the processing application, effectively rendering it unavailable.\nThis vulnerability highlights a critical risk where untrusted font data can bypass traditional input validation mechanisms to exhaust system resources, necessitating robust input filtering and library updates.",
  "technicalDetails": "The vulnerability resides in the CID font loader component of the FreeType library, which is responsible for parsing and interpreting CID-keyed (Character Identifier) fonts.\nThe root cause is an algorithmic complexity issue triggered during the handling of subroutine data associated with multiple font dictionaries.\nWhen a specially crafted CID-keyed font is presented to the parser, it forces the engine to perform repetitive, nested allocations and recursive decryption of subroutine structures.\nThe attack flow commences when a target application loads the malicious CID font. As FreeType processes the embedded subroutines across fragmented or intentionally bloated font dictionaries, the logic fails to enforce limits on resource consumption.\nBy manipulating the subroutine index references and font dictionary structures, an attacker can induce a state of thrashing, where the engine spends disproportionate CPU time and memory on decompressing and mapping font subroutines.\nBecause the vulnerability involves the repeated processing of font data within the CID loading pipeline, it can cause the memory footprint of the application to expand rapidly, potentially triggering an Out-Of-Memory (OOM) condition.\nExploitation does not require prior authentication or elevated privileges, as it relies on the standard rendering path of the library when processing user-provided content.\nThe impact is limited to resource exhaustion rather than arbitrary code execution, although the resulting application hang or crash serves as a effective DoS vector.\nThis flaw underscores the risks associated with parsing complex, binary-encoded font formats without strict bounds checking on internal subroutine recursion and resource allocation limits."
}
CVE-2026-95512: FreeType CID Font DoS Vulnerability (MEDIUM Severity, CVSS: 5.5) | Sceawere