An update that solves one vulnerability can now be installed.. # Security update for fontforge Announcement ID: SUSE-SU-2026:21375-1 Release Date: 2026-04-22T10:52:20Z Rating: important References: * bsc#1256031 Cross-References: * CVE-2025-15270 CVSS scores: * CVE-2025-15270 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15270 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for fontforge fixes the following issues: * CVE-2025-15270: lack of proper validation of user-supplied data when parsing SFD files can lead to OOB writes and arbitrary code execution (bsc#1256031). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-620=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-620=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * fontforge-debugsource-20251009-160000.2.1 * fontforge-debuginfo-20251009-160000.2.1 * fontforge-devel-20251009-160000.2.1 * fontforge-20251009-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * fontforge-doc-20251009-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * fontforge-debugsource-20251009-160000.2.1 * fontforge-debuginfo-20251009-160000.2.1 * fontforge-devel-20251009-160000.2.1 * fontforge-20251009-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * fontforge-doc-20251009-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15270.html *https://bugzilla.suse.com/show_bug.cgi?id=1256031 . Critical SUSE update for fontforge addresses important security issues with potential OOB writes and code execution risks.. SUSE update,fontforge security,OOB write risk,arbitrary code execution. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for fontforge Announcement ID: SUSE-SU-2026:1636-1 Release Date: 2026-04-27T16:55:28Z Rating: important References: * bsc#1256031 Cross-References: * CVE-2025-15270 CVSS scores: * CVE-2025-15270 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15270 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for fontforge fixes the following issue: * CVE-2025-15270: Remote code execution via malicious SFD file parsing (bsc#1256031). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patchSUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1636=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1636=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1636=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1636=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1636=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1636=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1636=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1636=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1636=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1636=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1636=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.15.1 * fontforge-debuginfo-20200314-150200.3.15.1 * fontforge-debugsource-20200314-150200.3.15.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * fontforge-20200314-150200.3.15.1 * fontforge-debuginfo-20200314-150200.3.15.1 * fontforge-debugsource-20200314-150200.3.15.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * fontforge-20200314-150200.3.15.1 * fontforge-debuginfo-20200314-150200.3.15.1 * fontforge-debugsource-20200314-150200.3.15.1 * SUSE LinuxEnterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * fontforge-20200314-150200.3.15.1 * fontforge-debuginfo-20200314-150200.3.15.1 * fontforge-debugsource-20200314-150200.3.15.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * fontforge-20200314-150200.3.15.1 * fontforge-debuginfo-20200314-150200.3.15.1 * fontforge-debugsource-20200314-150200.3.15.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.15.1 * fontforge-debuginfo-20200314-150200.3.15.1 * fontforge-debugsource-20200314-150200.3.15.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.15.1 * fontforge-debuginfo-20200314-150200.3.15.1 * fontforge-debugsource-20200314-150200.3.15.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.15.1 * fontforge-debuginfo-20200314-150200.3.15.1 * fontforge-debugsource-20200314-150200.3.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * fontforge-20200314-150200.3.15.1 * fontforge-debuginfo-20200314-150200.3.15.1 * fontforge-debugsource-20200314-150200.3.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * fontforge-20200314-150200.3.15.1 * fontforge-debuginfo-20200314-150200.3.15.1 * fontforge-debugsource-20200314-150200.3.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * fontforge-20200314-150200.3.15.1 * fontforge-debuginfo-20200314-150200.3.15.1 * fontforge-debugsource-20200314-150200.3.15.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15270.html * https://bugzilla.suse.com/show_bug.cgi?id=1256031 . Fix for important remote code execution issue in fontforge on SUSE. Update now for optimal security.. fontforge security issue, SUSE update, remote code execution, vulnerabilityfix, fontforge patch. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-7677 http://linux.oracle.com/errata/ELSA-2026-7677.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: fontforge-20200314-7.el8_10.i686.rpm fontforge-20200314-7.el8_10.x86_64.rpm aarch64: fontforge-20200314-7.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/fontforge-20200314-7.el8_10.src.rpm Related CVEs: CVE-2025-15269 CVE-2025-15270 CVE-2025-15275 CVE-2025-15279 Description of changes: [20200314-7] - Resolves: RHEL-138168 CVE-2025-15270 SFD File Parsing Remote Code Execution Vulnerability - Resolves: RHEL-138174 CVE-2025-15279 GUtils BMP File Parsing Heap-based Buffer Overflow - Resolves: RHEL-138190 CVE-2025-15275 SFD File Parsing Heap-based Buffer Overflow - Resolves: RHEL-138140 CVE-2025-15269 SFD File Parsing Use-After-Free [20200314-6] - Resolves: RHEL-26715 - fontforge: various flaws (CVE-2024-25081 and CVE-2024-25082) _______________________________________________ El-errata mailing list
Important: fontforge security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:7677", "synopsis": "Important: fontforge security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for fontforge.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "FontForge is a font editor for outline and bitmap fonts. It supports a range of font formats, including PostScript (ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts. \n\nSecurity Fix(es):\n\n* fontforge: FontForge: Remote Code Execution via heap-based buffer overflow in BMP file parsing (CVE-2025-15279)\n\n* fontforge: FontForge: Remote Code Execution via Use-After-Free in SFD file parsing (CVE-2025-15269)\n\n* fontforge: FontForge: Arbitrary code execution via SFD file parsing buffer overflow (CVE-2025-15275)\n\n* fontforge: FontForge: Remote Code Execution via malicious SFD file parsing (CVE-2025-15270)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2426421", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426421", "description": ""}, {"ticket": "2426423", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426423", "description": ""}, {"ticket": "2426429", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426429", "description": ""}, {"ticket": "2426434", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426434", "description": ""}], "cves": [{"name": "CVE-2025-15269", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15269","cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-416"}, {"name": "CVE-2025-15270", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15270", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-129"}, {"name": "CVE-2025-15275", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15275", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-122"}, {"name": "CVE-2025-15279", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15279", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-122"}], "references": [], "publishedAt": "2026-04-14T12:01:52.852600Z", "rpms": {"Rocky Linux 8": {"nvras": ["fontforge-0:20200314-7.el8_10.aarch64.rpm", "fontforge-0:20200314-7.el8_10.i686.rpm", "fontforge-0:20200314-7.el8_10.src.rpm", "fontforge-0:20200314-7.el8_10.x86_64.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.aarch64.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.i686.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.x86_64.rpm", "fontforge-debugsource-0:20200314-7.el8_10.aarch64.rpm", "fontforge-debugsource-0:20200314-7.el8_10.i686.rpm", "fontforge-debugsource-0:20200314-7.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. fontforge security update for Rocky Linux 8 addresses remote code execution risks and buffer overflows. Important security patch details here.. fontforge security update, Rocky Linux security, remote code execution, buffer overflow fix, important security patch. . Severity: Important. LinuxSecurity.com Team
Important: fontforge security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:7677", "synopsis": "Important: fontforge security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for fontforge.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "FontForge is a font editor for outline and bitmap fonts. It supports a range of font formats, including PostScript (ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts. \n\nSecurity Fix(es):\n\n* fontforge: FontForge: Remote Code Execution via heap-based buffer overflow in BMP file parsing (CVE-2025-15279)\n\n* fontforge: FontForge: Remote Code Execution via Use-After-Free in SFD file parsing (CVE-2025-15269)\n\n* fontforge: FontForge: Arbitrary code execution via SFD file parsing buffer overflow (CVE-2025-15275)\n\n* fontforge: FontForge: Remote Code Execution via malicious SFD file parsing (CVE-2025-15270)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2426421", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426421", "description": ""}, {"ticket": "2426423", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426423", "description": ""}, {"ticket": "2426429", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426429", "description": ""}, {"ticket": "2426434", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426434", "description": ""}], "cves": [{"name": "CVE-2025-15269", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15269","cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-416"}, {"name": "CVE-2025-15270", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15270", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-129"}, {"name": "CVE-2025-15275", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15275", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-122"}, {"name": "CVE-2025-15279", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15279", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-122"}], "references": [], "publishedAt": "2026-04-14T12:01:52.852600Z", "rpms": {"Rocky Linux 8": {"nvras": ["fontforge-0:20200314-7.el8_10.aarch64.rpm", "fontforge-0:20200314-7.el8_10.i686.rpm", "fontforge-0:20200314-7.el8_10.src.rpm", "fontforge-0:20200314-7.el8_10.x86_64.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.aarch64.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.i686.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.x86_64.rpm", "fontforge-debugsource-0:20200314-7.el8_10.aarch64.rpm", "fontforge-debugsource-0:20200314-7.el8_10.i686.rpm", "fontforge-debugsource-0:20200314-7.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. FontForge on Rocky Linux 8 has significant security updates addressing remote code executions and buffer overflows.. Rocky Linux FontForge Update Remote Code Execution Buffer Overflow. . Severity: Important. LinuxSecurity.com Team
Important: fontforge security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:7677", "synopsis": "Important: fontforge security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for fontforge.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "FontForge is a font editor for outline and bitmap fonts. It supports a range of font formats, including PostScript (ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts. \n\nSecurity Fix(es):\n\n* fontforge: FontForge: Remote Code Execution via heap-based buffer overflow in BMP file parsing (CVE-2025-15279)\n\n* fontforge: FontForge: Remote Code Execution via Use-After-Free in SFD file parsing (CVE-2025-15269)\n\n* fontforge: FontForge: Arbitrary code execution via SFD file parsing buffer overflow (CVE-2025-15275)\n\n* fontforge: FontForge: Remote Code Execution via malicious SFD file parsing (CVE-2025-15270)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2426421", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426421", "description": ""}, {"ticket": "2426423", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426423", "description": ""}, {"ticket": "2426429", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426429", "description": ""}, {"ticket": "2426434", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426434", "description": ""}], "cves": [{"name": "CVE-2025-15269", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15269","cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-416"}, {"name": "CVE-2025-15270", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15270", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-129"}, {"name": "CVE-2025-15275", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15275", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-122"}, {"name": "CVE-2025-15279", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15279", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-122"}], "references": [], "publishedAt": "2026-04-14T12:01:52.852600Z", "rpms": {"Rocky Linux 8": {"nvras": ["fontforge-0:20200314-7.el8_10.aarch64.rpm", "fontforge-0:20200314-7.el8_10.i686.rpm", "fontforge-0:20200314-7.el8_10.src.rpm", "fontforge-0:20200314-7.el8_10.x86_64.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.aarch64.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.i686.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.x86_64.rpm", "fontforge-debugsource-0:20200314-7.el8_10.aarch64.rpm", "fontforge-debugsource-0:20200314-7.el8_10.i686.rpm", "fontforge-debugsource-0:20200314-7.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An important security update for fontforge on Rocky Linux addresses critical remote code execution risks.. fontforge security update, remote code execution, rocky linux advisory. . Severity: Important. LinuxSecurity.com Team
Important: fontforge security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:7677", "synopsis": "Important: fontforge security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for fontforge.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "FontForge is a font editor for outline and bitmap fonts. It supports a range of font formats, including PostScript (ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts. \n\nSecurity Fix(es):\n\n* fontforge: FontForge: Remote Code Execution via heap-based buffer overflow in BMP file parsing (CVE-2025-15279)\n\n* fontforge: FontForge: Remote Code Execution via Use-After-Free in SFD file parsing (CVE-2025-15269)\n\n* fontforge: FontForge: Arbitrary code execution via SFD file parsing buffer overflow (CVE-2025-15275)\n\n* fontforge: FontForge: Remote Code Execution via malicious SFD file parsing (CVE-2025-15270)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2426421", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426421", "description": ""}, {"ticket": "2426423", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426423", "description": ""}, {"ticket": "2426429", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426429", "description": ""}, {"ticket": "2426434", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426434", "description": ""}], "cves": [{"name": "CVE-2025-15269", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15269","cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-416"}, {"name": "CVE-2025-15270", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15270", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-129"}, {"name": "CVE-2025-15275", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15275", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-122"}, {"name": "CVE-2025-15279", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15279", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-122"}], "references": [], "publishedAt": "2026-04-14T12:01:52.852600Z", "rpms": {"Rocky Linux 8": {"nvras": ["fontforge-0:20200314-7.el8_10.aarch64.rpm", "fontforge-0:20200314-7.el8_10.i686.rpm", "fontforge-0:20200314-7.el8_10.src.rpm", "fontforge-0:20200314-7.el8_10.x86_64.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.aarch64.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.i686.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.x86_64.rpm", "fontforge-debugsource-0:20200314-7.el8_10.aarch64.rpm", "fontforge-debugsource-0:20200314-7.el8_10.i686.rpm", "fontforge-debugsource-0:20200314-7.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical fontforge update for Rocky Linux 8 addresses important security issues including remote code execution vulnerabilities.. fontforge update, Rocky Linux security, buffer overflow risk, remote code execution, security patch. . Severity: Important. LinuxSecurity.com Team
Important: fontforge security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:7677", "synopsis": "Important: fontforge security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for fontforge.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "FontForge is a font editor for outline and bitmap fonts. It supports a range of font formats, including PostScript (ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts. \n\nSecurity Fix(es):\n\n* fontforge: FontForge: Remote Code Execution via heap-based buffer overflow in BMP file parsing (CVE-2025-15279)\n\n* fontforge: FontForge: Remote Code Execution via Use-After-Free in SFD file parsing (CVE-2025-15269)\n\n* fontforge: FontForge: Arbitrary code execution via SFD file parsing buffer overflow (CVE-2025-15275)\n\n* fontforge: FontForge: Remote Code Execution via malicious SFD file parsing (CVE-2025-15270)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2426421", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426421", "description": ""}, {"ticket": "2426423", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426423", "description": ""}, {"ticket": "2426429", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426429", "description": ""}, {"ticket": "2426434", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2426434", "description": ""}], "cves": [{"name": "CVE-2025-15269", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15269","cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-416"}, {"name": "CVE-2025-15270", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15270", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-129"}, {"name": "CVE-2025-15275", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15275", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-122"}, {"name": "CVE-2025-15279", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15279", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-122"}], "references": [], "publishedAt": "2026-04-14T12:01:52.852600Z", "rpms": {"Rocky Linux 8": {"nvras": ["fontforge-0:20200314-7.el8_10.aarch64.rpm", "fontforge-0:20200314-7.el8_10.i686.rpm", "fontforge-0:20200314-7.el8_10.src.rpm", "fontforge-0:20200314-7.el8_10.x86_64.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.aarch64.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.i686.rpm", "fontforge-debuginfo-0:20200314-7.el8_10.x86_64.rpm", "fontforge-debugsource-0:20200314-7.el8_10.aarch64.rpm", "fontforge-debugsource-0:20200314-7.el8_10.i686.rpm", "fontforge-debugsource-0:20200314-7.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important fontforge security update on Rocky Linux addresses remote code execution threats and critical vulnerabilities with multiple CVEs.. Rocky Linux fontforge security important buffer overflow remote code execution. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.