{"schema_version":"1.8.0","id":"CVE-2026-23865","published":"2026-03-02T17:16:32.100Z","modified":"2026-08-07T20:58:45.282846Z","aliases":["BIT-java-2026-23865","BIT-java-min-2026-23865","BIT-jre-2026-23865"],"related":["ALSA-2026:9683","ALSA-2026:9686","ALSA-2026:9689","ALSA-2026:9693","CGA-52wq-gppq-x56q","SUSE-SU-2026:1703-1","SUSE-SU-2026:1704-1","SUSE-SU-2026:1705-1","SUSE-SU-2026:1731-1","SUSE-SU-2026:1732-1","SUSE-SU-2026:1955-1","SUSE-SU-2026:2036-1","SUSE-SU-2026:20726-1","SUSE-SU-2026:20730-1","SUSE-SU-2026:21543-1","SUSE-SU-2026:21551-1","SUSE-SU-2026:21552-1","SUSE-SU-2026:22750-1","SUSE-SU-2026:22815-1","SUSE-SU-2026:2624-1","openSUSE-SU-2026:10289-1","openSUSE-SU-2026:10636-1","openSUSE-SU-2026:10637-1","openSUSE-SU-2026:10638-1","openSUSE-SU-2026:10639-1","openSUSE-SU-2026:10656-1","openSUSE-SU-2026:10728-1","openSUSE-SU-2026:10893-1","openSUSE-SU-2026:20672-1","openSUSE-SU-2026:20680-1","openSUSE-SU-2026:20681-1","openSUSE-SU-2026:20943-1","openSUSE-SU-2026:20947-1","openSUSE-SU-2026:21362-1"],"details":"An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/freetype/freetype","events":[{"introduced":"920c5502cc3ddda88f6c7d85ee834ac611bb11cc"},{"last_affected":"42608f77f20749dd6ddc9e0536788eaad70ea4b5"},{"introduced":"007c46ebbf45fc9debeebc01c7739f725faee342"},{"last_affected":"526ec5c47b9ebccc4754c85ac0c0cdf7c85a5e9b"}],"database_specific":{"cpe":"cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.13.2"},{"last_affected":"2.13.3"},{"introduced":"2.14.0"},{"last_affected":"2.14.1"}],"source":"CPE_RANGE"}}],"versions":["VER-2-14-1","VER-2-14-0","VER-2-13-3","VER-2-13-2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23865.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/freetype/freetype","events":[{"introduced":"0"},{"fixed":"fc85a255849229c024c8e65f536fe1875d84841c"}],"database_specific":{"source":"REFERENCES"}}],"versions":["VER-2-14-1","VER-2-14-0","VER-2-13-3","VER-2-13-2","VER-2-13-1","VER-2-13-0","VER-2-12-1","VER-2-12-0","VER-2-11-1","VER-2-11-0","VER-2-10-4","VER-2-10-3","VER-2-10-2","VER-2-10-1","VER-2-10-0","VER-2-9-1","VER-2-9","VER-2-8-1","VER-2-8","VER-2-7-1","VER-2-7","VER-2-6-4","VER-2-6-3","VER-2-6-2","VER-2-6-1","VER-2-6","VER-2-5-5","VER-2-5-4","VER-2-5-3","VER-2-5-2","VER-2-5-1","VER-2-5-0-1","VER-2-5-0","VER-2-4-12","VER-2-4-12-beta","VER-2-4-11","VER-2-4-10","VER-2-4-9","VER-2-4-8","VER-2-4-7","VER-2-4-6","VER-2-4-5","VER-2-4-4","VER-2-4-3","VER-2-4-2","VER-2-4-1","VER-2-4-0","VER-2-3-12","VER-2-3-11","VER-2-3-10","VER-2-3-9","VER-2-3-8","VER-2-3-7","VER-2-3-6","VER-2-3-5-REAL","VER-2-3-5","VER-2-3-4","VER-2-3-3","VER-2-3-2","VER-2-3-1-FINAL","VER-2-3-1","VER-2-3-0-FINAL","VER-2-3-0-RC2","VER-2-3-0","VER-2-3-0-RC1","VER-2-2-1","VER-2-2-0-RC4","VER-2-2-0","VER-2-2-0-RC3","VER-2-2-0-RC2","VER-2-2-0-RC1","DATE-050920","VER-2-1-10","VER-2-1-9","VER-2-1-8","VER-2-1-8-RC1","import","VER-2-1-7","VER-2-1-6","VER-2-1-5-RC1","start","VER-2-1-4","VER-2-1-4-RC2","VER-2-1-4-RC1","VER-2-1-3","VER-2-1-3-RC3","VER-2-1-3-RC2","VER-2-1-3-RC1","VER-2-1-2","VER-2-1-2-RC1","VER-2-1-1","VER-2-1-1-RC1","freetype","VER-2-1-0","VER-2-0-8","VER-2-0-7","VER-2-0-6","PRE-2-0-6","VER-2-0-5","freetype2","VER-2-0-4","VER-2-0-3","VER-2-0-2","VER-2-0-2-TEST","VER-2-0-1","PRE-2-0-1","VER-2-0","RELEASE-2-0","BETA-8","BETA-7","BETA-6","BETA-5","VER-2-BETA4","VER-2-BETA3","VER-2-BETA2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23865.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"371595557651698550721007698133082557","length":4105},"id":"CVE-2026-23865-2ac371c1","signature_type":"Function","signature_version":"v1","source":"https://gitlab.com/freetype/freetype@fc85a255849229c024c8e65f536fe1875d84841c","target":{"file":"src/truetype/ttgxvar.c","function":"tt_var_load_item_variation_store"}},{"deprecated":false,"digest":{"line_hashes":["173775725118845386785921971932501480943","217990528756814337641523475873168464252","256299278966677633404315659859596614456","131613146236841817417653859910863912020","64709015543735491674836162189416750751","31847057092482650765499423577043743340","77677376389532582855417806035044380397","251390016063463307935723584293454852956"],"threshold":0.9},"id":"CVE-2026-23865-91cf58e3","signature_type":"Line","signature_version":"v1","source":"https://gitlab.com/freetype/freetype@fc85a255849229c024c8e65f536fe1875d84841c","target":{"file":"src/truetype/ttgxvar.c"}}],"vanir_signatures_modified":"2026-08-07T20:58:45Z"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/freetype/freetype","events":[{"introduced":"920c5502cc3ddda88f6c7d85ee834ac611bb11cc"},{"last_affected":"42608f77f20749dd6ddc9e0536788eaad70ea4b5"},{"introduced":"007c46ebbf45fc9debeebc01c7739f725faee342"},{"last_affected":"526ec5c47b9ebccc4754c85ac0c0cdf7c85a5e9b"}],"database_specific":{"cpe":"cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.13.2"},{"last_affected":"2.13.3"},{"introduced":"2.14.0"},{"last_affected":"2.14.1"}],"source":"CPE_RANGE"}}],"versions":["VER-2-14-1","VER-2-14-0","VER-2-13-3","VER-2-13-2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23865.json"}}],"references":[{"type":"ADVISORY","url":"https://sourceforge.net/projects/freetype/files/freetype2/2.14.2/"},{"type":"ADVISORY","url":"https://www.facebook.com/security/advisories/cve-2026-23865"},{"type":"FIX","url":"https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2026/03/03/8"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"}]}