Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Critical Remote Code Execution Vulnerabilities in Fedora 43 FontForge

fedora
Calendar Grey February 1, 2026
Dist Fedora Esm H88
Critical updates for FontForge on Fedora 43 address several security issues, enhancing software stability and safety.
Resolves: CVE-2025-15279, CVE-2025-15275, CVE-2025-15269

Summary

FontForge (former PfaEdit) is a font editor for outline and bitmap

fonts. It supports a range of font formats, including PostScript

(ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType

(Type2) and CID-keyed fonts.

Update Information:

Resolves: CVE-2025-15279, CVE-2025-15275, CVE-2025-15269

Change Log

* Fri Jan 23 2026 Parag Nemade - 20230101-19 - Resolves: CVE-2025-15279 - Resolves: CVE-2025-15275 - Resolves: CVE-2025-15269

References


[ 1 ] Bug #2426578 - CVE-2025-15269 fontforge: FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2426578 [ 2 ] Bug #2426591 - CVE-2025-15275 fontforge: FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2426591 [ 3 ] Bug #2426597 - CVE-2025-15279 fontforge: FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2426597

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-746c4a59e2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: fontforge
Product: Fedora 43
Version: 20230101
Release: 19.fc43
Summary: Outline and bitmap font editor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here