An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.facebook.com/security/advisories/cve-2025-27363 |
![]() ![]() |
History
Tue, 11 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-787 | |
Metrics |
ssvc
|
Tue, 11 Mar 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild. | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: facebook
Published: 2025-03-11T13:28:31.705Z
Updated: 2025-03-11T13:42:09.970Z
Reserved: 2025-02-21T19:53:14.160Z
Link: CVE-2025-27363

Updated: 2025-03-11T13:42:02.320Z

Status : Received
Published: 2025-03-11T14:15:25.427
Modified: 2025-03-11T14:15:25.427
Link: CVE-2025-27363

No data.