{"id":"CVE-2022-27404","details":"FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.","modified":"2026-05-18T05:53:43.633693566Z","published":"2022-04-22T00:00:00Z","related":["ALSA-2022:7745","ALSA-2022:8340","CGA-458p-2258-j84j","SUSE-SU-2022:3252-1","SUSE-SU-2022:3252-2","SUSE-SU-2025:20204-1","openSUSE-SU-2024:12279-1","openSUSE-SU-2024:12367-1","openSUSE-SU-2024:12395-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/27xxx/CVE-2022-27404.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/27xxx/CVE-2022-27404.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EFPNRKDLCXHZVYYQLQMP44UHLU32GA6Z/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FDU2FOEMCEF6WVR6ZBIH5MT5O7FAK6UP/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWQ7IB2A75MEHM63WEUXBYEC7OR5SGDY/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYVC2NPKKXKP3TWJWG4ONYWNO6ZPHLA5/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TCEMWCM46PKM4U5ENRASPKQD6JDOLKRU/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-27404"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202402-06"},{"type":"REPORT","url":"https://gitlab.freedesktop.org/freetype/freetype/-/issues/1138"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/freetype/freetype","events":[{"introduced":"0"},{"fixed":"e50798b72043c8b378caa46e0a854519f9028ae4"}],"database_specific":{"cpe":"cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"2.12.0"}]}}],"versions":["VER-2-11-1","VER-2-11-0","VER-2-10-4","VER-2-10-3","VER-2-10-2","VER-2-10-1","VER-2-10-0","VER-2-9-1","VER-2-9","VER-2-8-1","VER-2-8","VER-2-7-1","VER-2-7","VER-2-6-4","VER-2-6-3","VER-2-6-2","VER-2-6-1","VER-2-6","VER-2-5-5","VER-2-5-4","VER-2-5-3","VER-2-5-2","VER-2-5-1","VER-2-5-0-1","VER-2-5-0","VER-2-4-12","VER-2-4-12-beta","VER-2-4-11","VER-2-4-10","VER-2-4-9","VER-2-4-8","VER-2-4-7","VER-2-4-6","VER-2-4-5","VER-2-4-4","VER-2-4-3","VER-2-4-2","VER-2-4-1","VER-2-4-0","VER-2-3-12","VER-2-3-11","VER-2-3-10","VER-2-3-9","VER-2-3-8","VER-2-3-7","VER-2-3-6","VER-2-3-5-REAL","VER-2-3-5","VER-2-3-4","VER-2-3-3","VER-2-3-2","VER-2-3-1-FINAL","VER-2-3-1","VER-2-3-0-FINAL","VER-2-3-0-RC2","VER-2-3-0","VER-2-3-0-RC1","VER-2-2-1","VER-2-2-0-RC4","VER-2-2-0","VER-2-2-0-RC3","VER-2-2-0-RC2","VER-2-2-0-RC1","DATE-050920","VER-2-1-10","VER-2-1-9","VER-2-1-8","VER-2-1-8-RC1","import","VER-2-1-7","VER-2-1-6","VER-2-1-5-RC1","start","VER-2-1-4","VER-2-1-4-RC2","VER-2-1-4-RC1","VER-2-1-3","VER-2-1-3-RC3","VER-2-1-3-RC2","VER-2-1-3-RC1","VER-2-1-2","VER-2-1-2-RC1","VER-2-1-1","VER-2-1-1-RC1","freetype","VER-2-1-0","VER-2-0-8","VER-2-0-7","VER-2-0-6","PRE-2-0-6","VER-2-0-5","freetype2","VER-2-0-4","VER-2-0-3","VER-2-0-2","VER-2-0-2-TEST","VER-2-0-1","PRE-2-0-1","VER-2-0","RELEASE-2-0","BETA-8","BETA-7","BETA-6","BETA-5","VER-2-BETA4","VER-2-BETA3","VER-2-BETA2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-27404.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/freetype/freetype","events":[{"introduced":"0"},{"fixed":"e50798b72043c8b378caa46e0a854519f9028ae4"}],"database_specific":{"cpe":"cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"2.12.0"}]}}],"versions":["VER-2-11-1","VER-2-11-0","VER-2-10-4","VER-2-10-3","VER-2-10-2","VER-2-10-1","VER-2-10-0","VER-2-9-1","VER-2-9","VER-2-8-1","VER-2-8","VER-2-7-1","VER-2-7","VER-2-6-4","VER-2-6-3","VER-2-6-2","VER-2-6-1","VER-2-6","VER-2-5-5","VER-2-5-4","VER-2-5-3","VER-2-5-2","VER-2-5-1","VER-2-5-0-1","VER-2-5-0","VER-2-4-12","VER-2-4-12-beta","VER-2-4-11","VER-2-4-10","VER-2-4-9","VER-2-4-8","VER-2-4-7","VER-2-4-6","VER-2-4-5","VER-2-4-4","VER-2-4-3","VER-2-4-2","VER-2-4-1","VER-2-4-0","VER-2-3-12","VER-2-3-11","VER-2-3-10","VER-2-3-9","VER-2-3-8","VER-2-3-7","VER-2-3-6","VER-2-3-5-REAL","VER-2-3-5","VER-2-3-4","VER-2-3-3","VER-2-3-2","VER-2-3-1-FINAL","VER-2-3-1","VER-2-3-0-FINAL","VER-2-3-0-RC2","VER-2-3-0","VER-2-3-0-RC1","VER-2-2-1","VER-2-2-0-RC4","VER-2-2-0","VER-2-2-0-RC3","VER-2-2-0-RC2","VER-2-2-0-RC1","DATE-050920","VER-2-1-10","VER-2-1-9","VER-2-1-8","VER-2-1-8-RC1","import","VER-2-1-7","VER-2-1-6","VER-2-1-5-RC1","start","VER-2-1-4","VER-2-1-4-RC2","VER-2-1-4-RC1","VER-2-1-3","VER-2-1-3-RC3","VER-2-1-3-RC2","VER-2-1-3-RC1","VER-2-1-2","VER-2-1-2-RC1","VER-2-1-1","VER-2-1-1-RC1","freetype","VER-2-1-0","VER-2-0-8","VER-2-0-7","VER-2-0-6","PRE-2-0-6","VER-2-0-5","freetype2","VER-2-0-4","VER-2-0-3","VER-2-0-2","VER-2-0-2-TEST","VER-2-0-1","PRE-2-0-1","VER-2-0","RELEASE-2-0","BETA-8","BETA-7","BETA-6","BETA-5","VER-2-BETA4","VER-2-BETA3","VER-2-BETA2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-27404.json"}}],"schema_version":"1.7.5"}