CVE-2026-34085
ADVISORY - nistSummary
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
EPSS Score: 0.00012 (0.018)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Off-by-one Error
ADVISORY - redhat
Off-by-one Error
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in