### This update for freetype2 fixes the following issue: Update to freetype2 2.14.2: * CVE-2026-23865: Integer overflow in the tt_var_load_item_variation_store function (bsc#1259118). Changelog: * Several changes related to LCD filtering are implemented to achieve better performance and encourage sound practices. * Instead of blanket LCD filtering over the entire bitmap, it is now applied only to non-zero spans using direct rendering. This speeds up the ClearType- like rendering by more than 40% at sizes above 32 ppem. * Setting the filter weights with FT_Face_Properties is no longer supported. The default and light filters are optimized to work with any face. * The legacy libXft LCD filter algorithm is no longer provided. * A bunch of potential security problems have been found (bsc#1259118,
* bsc#1192869
* bsc#1217580
* bsc#1217584
* bsc#1217585
* bsc#1241661
* bsc#1252148
* bsc#1253245
* bsc#1258163
* bsc#1258167
* bsc#1259118
Cross-
* CVE-2021-42380
* CVE-2023-42363
* CVE-2023-42364
* CVE-2023-42365
* CVE-2025-46394
* CVE-2025-60876
* CVE-2026-23865
* CVE-2026-26157
* CVE-2026-26158
CVSS scores:
* CVE-2021-42380 ( SUSE ): 6.6 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2021-42380 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2021-42380 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-42363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2023-42363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2023-42364 ( SUSE ): 5.1
Get the latest Linux and open source security news straight to your inbox.