CVE-2025-27363

high KEV
Published 2025-03-31 ยท Modified 2025-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.5

Description

FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution.

CISA KEV

Vendor
FreeType
Product
FreeType
Due date
2025-05-27

Predictions

Exploit likelihood
99%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27
{Vendor advisory: cisa-kev โ€” This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://source.android.com/docs/security/bulletin/2025-05-01 ; https://nvd.nist.gov/vuln/detail/CVE-2025-27363}

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
arch Arch Fixed 1 release
VersionStatusFixed in
โ€” Fixed 2.13.3-3
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.13.1+dfsg-1
sid Fixed 2.13.1+dfsg-1
forky Fixed 2.13.1+dfsg-1
bullseye Fixed 2.10.4+dfsg-1+deb11u2
bookworm Fixed 2.12.1+dfsg-5+deb12u4
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.