CVE-2025-15270
Description
Important: fontforge security update
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description fontforge: FontForge: Remote Code Execution via malicious SFD file parsing Red Hat statement This vulnerability is rated Important for Red Hat products as it allows remote code execution in FontForge. Exploitation requires user interaction, where a target must open a specially crafted SFD file. This affects systems where FontForge is installed and used to process untrusted font files.โฆ
Description
fontforge: FontForge: Remote Code Execution via malicious SFD file parsing
Red Hat statement
This vulnerability is rated Important for Red Hat products as it allows remote code execution in FontForge. Exploitation requires user interaction, where a target must open a specially crafted SFD file. This affects systems where FontForge is installed and used to process untrusted font files.
CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | fontforge-0:20230101-15.el10_1 | RHSA-2026:6631 | 2026-04-06T00:00:00Z |
| Red Hat Enterprise Linux 10.0 Extended Update Support | fontforge-0:20230101-15.el10_0 | RHSA-2026:8875 | 2026-04-20T00:00:00Z |
| Red Hat Enterprise Linux 8 | fontforge-0:20200314-7.el8_10 | RHSA-2026:7677 | 2026-04-13T00:00:00Z |
| Red Hat Enterprise Linux 9 | fontforge-0:20201107-8.el9_7 | RHSA-2026:6628 | 2026-04-06T00:00:00Z |
| Red Hat Enterprise Linux 9.4 Extended Update Support | fontforge-0:20201107-7.el9_4 | RHSA-2026:7001 | 2026-04-08T00:00:00Z |
| Red Hat Enterprise Linux 9.6 Extended Update Support | fontforge-0:20201107-8.el9_6 | RHSA-2026:6635 | 2026-04-06T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | fontforge | Out of support scope |
| Red Hat Enterprise Linux 7 | fontforge | Not affected |
Apply commands
yum update -y fontforge
# or:
dnf upgrade -y fontforge
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 7 | Not affected |
OS impact
Debian Affected 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Affected | โ |
| sid | Affected | โ |
| forky | Affected | โ |
| bullseye | Affected | โ |
| bookworm | Affected | โ |
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| โ | Affected | โ |
AlmaLinux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | fontforge-20201107-8.el9_7.ppc64le.rpm |
Red Hat Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | โ |
| 8 | Fixed | โ |
Rocky Linux Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | โ |
| 8 | Fixed | โ |
References
- https://access.redhat.com/errata/RHSA-2026:6628
- https://security-tracker.debian.org/tracker/CVE-2025-15270
- https://www.suse.com/security/cve/CVE-2025-15270.html
- https://errata.rockylinux.org/RLSA-2026:6628
- https://bugzilla.redhat.com/2426434
- https://errata.almalinux.org/9/ALSA-2026-6628.html
- https://access.redhat.com/errata/RHSA-2026:7677
- https://bugzilla.redhat.com/2426421
- https://bugzilla.redhat.com/2426423
- https://bugzilla.redhat.com/2426429
- https://errata.almalinux.org/8/ALSA-2026-7677.html
- https://errata.rockylinux.org/RLSA-2026:7677
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.