Impact
A flaw in FreeType’s CID font loader allows a remote attacker to craft or embed a CID‑keyed font that, when processed, repeatedly allocates and decrypts subroutine data across multiple font dictionaries, exhausting memory and CPU resources and resulting in a denial of service for the application or service rendering the font. This vulnerability falls under the OWASP CWE‑400 classification of uncontrolled resource consumption.
Affected Systems
Red Hat Enterprise Linux versions 6 through 10, Red Hat Hardened Images, and Red Hat build of OpenJDK 11 ELS are affected through the bundled FreeType libraries. Systems using Red Hat’s Hummingbird product are also impacted. The vulnerability is present in the default FreeType packages shipped with these operating systems and Java distributions.
Risk and Exploitability
The CVSS base score of 5.5 indicates a moderate severity; the EPSS score is not available, so the current likelihood of exploitation is unclear, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote adversary enticing a user to open or view content that references the specially crafted font—common vectors include malicious PDFs, web pages, or documents. If an application employing FreeType renders such a font without proper safety checks, the memory and CPU drain will make the application unresponsive or cause it to terminate, thereby disrupting services.
OpenCVE Enrichment