Re: Vulnerability Report: 32-bit Integer Overflow in src/sdf/ftsdf.c leading to Heap Buffer Overflow
Werner LEMBERG <[email protected]> Wed, 11 Mar 2026 12:59:01 +0000
| Newsgroups | gmane.comp.fonts.freetype.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello Gabriel,
Sorry for the late reply.
> I am writing to report a critical security vulnerability identified
> in the FreeType 2 SDF (Signed Distance Field) engine, specifically
> within the src/sdf/ftsdf.c file.
Thanks for the report. This should already be fixed with commit
dd66971f3c (from Feb. 23rd, which has been committed exactly in the
time between finishing the report and sending it to the FreeType
list).
Please test.
Werner
PS: For future reports that are discussing security problems please
file an issue in our tracker
https://gitlab.freedesktop.org/freetype/freetype/-/issues
and set the confidentiality flag.