Updated freetype2 package fixes a security vulnerability
Publication date: 09 Oct 2026Modification date: 09 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-50811
Description
An out-of-bounds read vulnerability exists in FreeType 2.14.3 and
versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in
src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by
FT_Get_Var_Design_Coordinates. (CVE-2026-50811)
References
- https://bugs.mageia.org/show_bug.cgi?id=35931
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/ZFL5DU5VYR7IO6AIBJXA3PU262H5MJCS/
- https://gitlab.freedesktop.org/freetype/freetype/-/work_items/1436
- https://ubuntu.com/security/notices/USN-8562-1
- https://www.cve.org/CVERecord?id=CVE-2026-50811
SRPMS
10/tainted
- freetype2-2.14.2-1.1.mga10.tainted