[ GLSA 202608-02 ] FreeType: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178657885140.8.12462422017298716008@5abbdadb2b16>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-02
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: FreeType: Multiple Vulnerabilities
     Date: August 12, 2026
     Bugs: #970886, #971490
       ID: 202608-02

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in FreeType, one of which
includes information leak.

Background
==========

FreeType is a software font engine that is designed to be small,
efficient, highly customizable, and portable while capable of producing
high-quality output (glyph images).

Affected packages
=================

Package              Vulnerable    Unaffected
-------------------  ------------  ------------
media-libs/freetype  < 2.14.3      >= 2.14.3

Description
===========

Multiple vulnerabilities have been discovered in FreeType. Please review
the CVE identifiers referenced below for details.

Impact
======

One of the possible outcomes allows for an out-of-bounds read. Please
review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All FreeType users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=media-libs/freetype-2.14.3"

References
==========

[ 1 ] CVE-2026-22007
      https://nvd.nist.gov/vuln/detail/CVE-2026-22007
[ 2 ] CVE-2026-22008
      https://nvd.nist.gov/vuln/detail/CVE-2026-22008
[ 3 ] CVE-2026-22013
      https://nvd.nist.gov/vuln/detail/CVE-2026-22013
[ 4 ] CVE-2026-22016
      https://nvd.nist.gov/vuln/detail/CVE-2026-22016
[ 5 ] CVE-2026-22018
      https://nvd.nist.gov/vuln/detail/CVE-2026-22018
[ 6 ] CVE-2026-22021
      https://nvd.nist.gov/vuln/detail/CVE-2026-22021
[ 7 ] CVE-2026-23865
      https://nvd.nist.gov/vuln/detail/CVE-2026-23865
[ 8 ] CVE-2026-34268
      https://nvd.nist.gov/vuln/detail/CVE-2026-34268
[ 9 ] CVE-2026-34282
      https://nvd.nist.gov/vuln/detail/CVE-2026-34282

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-02

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmp9B6MACgkQFMQkOaVy
+9nDSxAAgfe4SqWYaJoK1fkLlUSAAQccij5URHpJb5xXa1gmbi2OvbKeiYc2hmJu
VIjy9JPlJsydSKobUXN2cyyR2pJiZYQlhsqpKK7HE6k7jged5GwDHboHfrORX1BF
XnG6vqQkimHCmTimRH1FB+e+tN0oJmWr9MGGLpsKo2ek+esRRtKeGG4qIPrZAHZ0
mFIZCCv0Mcfq0146TX8X7irEAdfeS1Lk0Zc5c2E3nrv7RdZFPKIvmLQ/IOOwhi03
cTVpVVnLv/MURPDq1EKuVWF6sKEbNIeZn9bW904EJzbYOdA48OWoPKd74Calmv+h
jWy0f6y6vYWWd0HvSS/x7B68HqTfH4u23ucyb6nmish5ZtDF6uSzJnsGlF6et2v1
WMqWxNg5JZaQq8/zN4REai6hgUpQJe45XRlDy0uul5tCcdUt8PhXVUcDxWeTYRCJ
Spsgaa2eL5MtkfVKoexRUgl0Eas4pOuymK3378tJK9p2tAc566E9uRSargHIQvxi
2SGhmYGeafF/DfM0NsMbxove9HtvF6MOm9ssznZU81XaMRNrG6lISRuDCmmorQr6
Z5L60VDwnbD7jzfUUqKX20t/vOXZlmTX1MtDwdGXBUC1yLtfQv7jCkVt7xwPfBks
62f2VaDGGcdEpyOahwqjxR7qrJKRpB/pre/MJDqritR+3PZESRM=
=o1aR
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.