Advisories ยป MGASA-2026-0472

Updated freetype2 package fixes a security vulnerability

Publication date: 09 Oct 2026
Modification date: 09 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-50811

Description

An out-of-bounds read vulnerability exists in FreeType 2.14.3 and
versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in
src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by
FT_Get_Var_Design_Coordinates. (CVE-2026-50811)
                

References

SRPMS

10/tainted