{"id":"CVE-2025-27363","details":"An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.","aliases":["A-399065987","ASB-A-399065987"],"modified":"2026-05-28T04:10:31.629830855Z","published":"2025-03-11T13:28:31.705Z","related":["ALSA-2025:3421","ALSA-2025:8292","SUSE-SU-2025:0960-1","SUSE-SU-2025:0998-1"],"database_specific":{"cna_assigner":"facebook","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0.0.0"},{"last_affected":"2.13.0"}]}],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27363.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/13/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/13/11"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/13/12"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/13/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/13/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/13/8"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/14/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/14/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/14/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/14/4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/05/06/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/16/5"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/19/3"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00030.html"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27363"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27363.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27363"},{"type":"ADVISORY","url":"https://source.android.com/docs/security/bulletin/2025-05-01"},{"type":"ADVISORY","url":"https://www.facebook.com/security/advisories/cve-2025-27363"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/freetype/freetype","events":[{"introduced":"0"},{"last_affected":"de8b92dd7ec634e9e2b25ef534c54a3537555c11"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.13.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*"}}],"versions":["VER-2-13-0","VER-2-12-1","VER-2-12-0","VER-2-11-1","VER-2-11-0","VER-2-10-4","VER-2-10-3","VER-2-10-2","VER-2-10-1","VER-2-10-0","VER-2-9-1","VER-2-9","VER-2-8-1","VER-2-8","VER-2-7-1","VER-2-7","VER-2-6-4","VER-2-6-3","VER-2-6-2","VER-2-6-1","VER-2-6","VER-2-5-5","VER-2-5-4","VER-2-5-3","VER-2-5-2","VER-2-5-1","VER-2-5-0-1","VER-2-5-0","VER-2-4-12","VER-2-4-12-beta","VER-2-4-11","VER-2-4-10","VER-2-4-9","VER-2-4-8","VER-2-4-7","VER-2-4-6","VER-2-4-5","VER-2-4-4","VER-2-4-3","VER-2-4-2","VER-2-4-1","VER-2-4-0","VER-2-3-12","VER-2-3-11","VER-2-3-10","VER-2-3-9","VER-2-3-8","VER-2-3-7","VER-2-3-6","VER-2-3-5-REAL","VER-2-3-5","VER-2-3-4","VER-2-3-3","VER-2-3-2","VER-2-3-1-FINAL","VER-2-3-1","VER-2-3-0-FINAL","VER-2-3-0-RC2","VER-2-3-0","VER-2-3-0-RC1","VER-2-2-1","VER-2-2-0-RC4","VER-2-2-0","VER-2-2-0-RC3","VER-2-2-0-RC2","VER-2-2-0-RC1","DATE-050920","VER-2-1-10","VER-2-1-9","VER-2-1-8","VER-2-1-8-RC1","import","VER-2-1-7","VER-2-1-6","VER-2-1-5-RC1","start","VER-2-1-4","VER-2-1-4-RC2","VER-2-1-4-RC1","VER-2-1-3","VER-2-1-3-RC3","VER-2-1-3-RC2","VER-2-1-3-RC1","VER-2-1-2","VER-2-1-2-RC1","VER-2-1-1","VER-2-1-1-RC1","freetype","VER-2-1-0","VER-2-0-8","VER-2-0-7","VER-2-0-6","PRE-2-0-6","VER-2-0-5","freetype2","VER-2-0-4","VER-2-0-3","VER-2-0-2","VER-2-0-2-TEST","VER-2-0-1","PRE-2-0-1","VER-2-0","RELEASE-2-0","BETA-8","BETA-7","BETA-6","BETA-5","VER-2-BETA4","VER-2-BETA3","VER-2-BETA2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-27363.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/freetype/freetype","events":[{"introduced":"0"},{"last_affected":"de8b92dd7ec634e9e2b25ef534c54a3537555c11"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.13.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*"}}],"versions":["VER-2-13-0","VER-2-12-1","VER-2-12-0","VER-2-11-1","VER-2-11-0","VER-2-10-4","VER-2-10-3","VER-2-10-2","VER-2-10-1","VER-2-10-0","VER-2-9-1","VER-2-9","VER-2-8-1","VER-2-8","VER-2-7-1","VER-2-7","VER-2-6-4","VER-2-6-3","VER-2-6-2","VER-2-6-1","VER-2-6","VER-2-5-5","VER-2-5-4","VER-2-5-3","VER-2-5-2","VER-2-5-1","VER-2-5-0-1","VER-2-5-0","VER-2-4-12","VER-2-4-12-beta","VER-2-4-11","VER-2-4-10","VER-2-4-9","VER-2-4-8","VER-2-4-7","VER-2-4-6","VER-2-4-5","VER-2-4-4","VER-2-4-3","VER-2-4-2","VER-2-4-1","VER-2-4-0","VER-2-3-12","VER-2-3-11","VER-2-3-10","VER-2-3-9","VER-2-3-8","VER-2-3-7","VER-2-3-6","VER-2-3-5-REAL","VER-2-3-5","VER-2-3-4","VER-2-3-3","VER-2-3-2","VER-2-3-1-FINAL","VER-2-3-1","VER-2-3-0-FINAL","VER-2-3-0-RC2","VER-2-3-0","VER-2-3-0-RC1","VER-2-2-1","VER-2-2-0-RC4","VER-2-2-0","VER-2-2-0-RC3","VER-2-2-0-RC2","VER-2-2-0-RC1","DATE-050920","VER-2-1-10","VER-2-1-9","VER-2-1-8","VER-2-1-8-RC1","import","VER-2-1-7","VER-2-1-6","VER-2-1-5-RC1","start","VER-2-1-4","VER-2-1-4-RC2","VER-2-1-4-RC1","VER-2-1-3","VER-2-1-3-RC3","VER-2-1-3-RC2","VER-2-1-3-RC1","VER-2-1-2","VER-2-1-2-RC1","VER-2-1-1","VER-2-1-1-RC1","freetype","VER-2-1-0","VER-2-0-8","VER-2-0-7","VER-2-0-6","PRE-2-0-6","VER-2-0-5","freetype2","VER-2-0-4","VER-2-0-3","VER-2-0-2","VER-2-0-2-TEST","VER-2-0-1","PRE-2-0-1","VER-2-0","RELEASE-2-0","BETA-8","BETA-7","BETA-6","BETA-5","VER-2-BETA4","VER-2-BETA3","VER-2-BETA2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-27363.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C/CR:H/IR:H/AR:H/MAV:N/MAC:L/MPR:N/MUI:N/MS:U/MC:H/MI:H/MA:H"}]}