Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 43 perl-HarfBuzz-Shaper Critical Null Pointer Issue CVE-2026-22693

fedora
Calendar Grey January 29, 2026
Dist Fedora Esm H88
Fedora 43 update for perl-HarfBuzz-Shaper addresses access issues and null pointer impact from CVE-2026-22693.
Merge branch 'rawhide' into f43 Upgrade to upstream 0.032 to fix CVE-2026-22693.

Summary

HarfBuzz::Shaper is a perl module that provides access to a small

subset of the native HarfBuzz library.

The subset is suitable for typesetting programs that need to deal with

complex languages like Devanagari.

This module is intended to be used with module L.

Update Information:

Merge branch 'rawhide' into f43 Upgrade to upstream 0.032 to fix CVE-2026-22693.

Change Log

* Tue Jan 20 2026 Johan Vromans - 0.033-1 - Upgrade to upstream. Eliminates distributing harfbuzz sources. * Sat Jan 17 2026 Fedora Release Engineering - 0.032-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Wed Jan 14 2026 Johan Vromans - 0.032-1 - Upgrade to upstream 0.032. Upgrade embedded harfbuzz to 12.3.0 to fix CVE-2026-22693.

References


[ 1 ] Bug #2342927 - perl-HarfBuzz-Shaper-0.033 is available https://bugzilla.redhat.com/show_bug.cgi?id=2342927 [ 2 ] Bug #2429296 - CVE-2026-22693 perl-HarfBuzz-Shaper: Null Pointer Dereference in harfbuzz [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2429296 [ 3 ] Bug #2430874 - CVE-2026-0943 perl-HarfBuzz-Shaper: HarfBuzz::Shaper null pointer dereference vulnerability [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2430874

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2b5249b4b6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: perl-HarfBuzz-Shaper
Product: Fedora 43
Version: 0.033
Release: 2.fc43
Summary: Access to a small subset of the native HarfBuzz library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here