CVE-2025-15270

high
Published 2026-04-06 ยท Modified 2026-04-08
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.0

Description

Important: fontforge security update

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description fontforge: FontForge: Remote Code Execution via malicious SFD file parsing Red Hat statement This vulnerability is rated Important for Red Hat products as it allows remote code execution in FontForge. Exploitation requires user interaction, where a target must open a specially crafted SFD file. This affects systems where FontForge is installed and used to process untrusted font files.โ€ฆ

Description

fontforge: FontForge: Remote Code Execution via malicious SFD file parsing

Red Hat statement

This vulnerability is rated Important for Red Hat products as it allows remote code execution in FontForge. Exploitation requires user interaction, where a target must open a specially crafted SFD file. This affects systems where FontForge is installed and used to process untrusted font files.

CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10fontforge-0:20230101-15.el10_1RHSA-2026:66312026-04-06T00:00:00Z
Red Hat Enterprise Linux 10.0 Extended Update Supportfontforge-0:20230101-15.el10_0RHSA-2026:88752026-04-20T00:00:00Z
Red Hat Enterprise Linux 8fontforge-0:20200314-7.el8_10RHSA-2026:76772026-04-13T00:00:00Z
Red Hat Enterprise Linux 9fontforge-0:20201107-8.el9_7RHSA-2026:66282026-04-06T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportfontforge-0:20201107-7.el9_4RHSA-2026:70012026-04-08T00:00:00Z
Red Hat Enterprise Linux 9.6 Extended Update Supportfontforge-0:20201107-8.el9_6RHSA-2026:66352026-04-06T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6fontforgeOut of support scope
Red Hat Enterprise Linux 7fontforgeNot affected

Apply commands

bash fix
Apply RHSA-2026:6631 for Red Hat Enterprise Linux 10
yum update -y fontforge
# or:
dnf upgrade -y fontforge

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 7Not affected

OS impact

debian Debian Affected 5 releases
VersionStatusFixed in
trixie Affected โ€”
sid Affected โ€”
forky Affected โ€”
bullseye Affected โ€”
bookworm Affected โ€”
suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed fontforge-20201107-8.el9_7.ppc64le.rpm
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.