{"id":"CVE-2026-95512","summary":"Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader","details":"A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.","modified":"2026-10-04T07:01:41.073653Z","published":"2026-10-02T09:05:11.245Z","database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-400"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95512.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://catalog.redhat.com/software/containers/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:74952"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-95512"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95512.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95512"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2462295"},{"type":"FIX","url":"https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/freetype/freetype","events":[{"introduced":"0"},{"fixed":"f3ca71c9900fe860849b3163a6e2c1e765b291d9"}],"database_specific":{"source":"REFERENCES"}}],"versions":["VER-2-14-3","VER-2-14-2","VER-2-14-1","VER-2-14-0","VER-2-13-3","VER-2-13-2","VER-2-13-1","VER-2-13-0","VER-2-12-1","VER-2-12-0","VER-2-11-1","VER-2-11-0","VER-2-10-4","VER-2-10-3","VER-2-10-2","VER-2-10-1","VER-2-10-0","VER-2-9-1","VER-2-9","VER-2-8-1","VER-2-8","VER-2-7-1","VER-2-7","VER-2-6-4","VER-2-6-3","VER-2-6-2","VER-2-6-1","VER-2-6","VER-2-5-5","VER-2-5-4","VER-2-5-3","VER-2-5-2","VER-2-5-1","VER-2-5-0-1","VER-2-5-0","VER-2-4-12","VER-2-4-12-beta","VER-2-4-11","VER-2-4-10","VER-2-4-9","VER-2-4-8","VER-2-4-7","VER-2-4-6","VER-2-4-5","VER-2-4-4","VER-2-4-3","VER-2-4-2","VER-2-4-1","VER-2-4-0","VER-2-3-12","VER-2-3-11","VER-2-3-10","VER-2-3-9","VER-2-3-8","VER-2-3-7","VER-2-3-6","VER-2-3-5-REAL","VER-2-3-5","VER-2-3-4","VER-2-3-3","VER-2-3-2","VER-2-3-1-FINAL","VER-2-3-1","VER-2-3-0-FINAL","VER-2-3-0-RC2","VER-2-3-0","VER-2-3-0-RC1","VER-2-2-1","VER-2-2-0-RC4","VER-2-2-0","VER-2-2-0-RC3","VER-2-2-0-RC2","VER-2-2-0-RC1","DATE-050920","VER-2-1-10","VER-2-1-9","VER-2-1-8","VER-2-1-8-RC1","import","VER-2-1-7","VER-2-1-6","VER-2-1-5-RC1","start","VER-2-1-4","VER-2-1-4-RC2","VER-2-1-4-RC1","VER-2-1-3","VER-2-1-3-RC3","VER-2-1-3-RC2","VER-2-1-3-RC1","VER-2-1-2","VER-2-1-2-RC1","VER-2-1-1","VER-2-1-1-RC1","freetype","VER-2-1-0","VER-2-0-8","VER-2-0-7","VER-2-0-6","PRE-2-0-6","VER-2-0-5","freetype2","VER-2-0-4","VER-2-0-3","VER-2-0-2","VER-2-0-2-TEST","VER-2-0-1","PRE-2-0-1","VER-2-0","RELEASE-2-0","BETA-8","BETA-7","BETA-6","BETA-5","VER-2-BETA4","VER-2-BETA3","VER-2-BETA2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-95512.json","vanir_signatures_modified":"2026-10-04T07:01:41Z","vanir_signatures":[{"signature_version":"v1","source":"https://gitlab.freedesktop.org/freetype/freetype@f3ca71c9900fe860849b3163a6e2c1e765b291d9","target":{"file":"src/cid/cidload.c","function":"cid_read_subrs"},"deprecated":false,"digest":{"length":2256,"function_hash":"259200994032010936063787211057547714652"},"id":"CVE-2026-95512-12e845e8","signature_type":"Function"},{"id":"CVE-2026-95512-b1c4b76c","signature_type":"Line","signature_version":"v1","source":"https://gitlab.freedesktop.org/freetype/freetype@f3ca71c9900fe860849b3163a6e2c1e765b291d9","target":{"file":"src/cid/cidload.c"},"deprecated":false,"digest":{"line_hashes":["152937411635740086459520367050448665719","258548005201226190369177455865505328921","163262093634245156726322638498547476430","76349760283979859109882062457365616182","75300275272473090163666232914083773528","111457709484502055113258564062513310293","166662914078464676203562358056447768179","195681934156291992527615608160036954699"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}