Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 9 FontForge Critical Remote Code Exec Risks MGASA-2026-0034

mageia
Calendar Grey February 9, 2026
Dist Mageia Esm H88
Updated FontForge packages address critical remote code execution risks from use-after-free and buffer overflow issues.
MGASA-2026-0034 - Updated fontforge packages fix security vulnerabilities

Summary

Description: FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. (CVE-2025-15269) FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. (CVE-2025-15270) FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. (CVE-2025-15275) FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. (CVE-2025-15279)

References

- https://bugs.mageia.org/show_bug.cgi?id=35091

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NFM3OPUTYR55GA65K3XOPK3FXAH7EWEJ/

- https://github.com/advisories/GHSA-hp8x-4h95-9799

- https://www.cve.org/CVERecord?id=CVE-2025-15269

- https://www.cve.org/CVERecord?id=CVE-2025-15270

- https://www.cve.org/CVERecord?id=CVE-2025-15275

- https://www.cve.org/CVERecord?id=CVE-2025-15279

Resolution

SRPMS

- 9/core/fontforge-20220308-2.2.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 09 Feb 2026
URL: https://advisories.mageia.org/MGASA-2026-0034.html
Type: security
CVE: CVE-2025-15269, CVE-2025-15270, CVE-2025-15275, CVE-2025-15279

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here