Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <87v7dmrejr.fsf@gentoo.org>
Date: Sun, 19 Apr 2026 19:27:36 +0100
From: Sam James <sam@...too.org>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2025-27363: FontForge affected by FreeType
 heap-buffer-overflow; upstream maintainer declines under
 Community-guidelines #D1

yangjincheng1998@...il.com writes:

> Hello oss-security,
>
> [...]
>
> == Upstream maintainer response ==
> We reported this downstream impact to FontForge upstream as
> https://github.com/fontforge/fontforge/issues/5799 (2026-04-15).
> The issue was closed within hours under "Community-guidelines #D1",
> which states that the project does not accept security reports without
> an accompanying fix PR.
>

I'll note that the linked #D1 guidelines [0] say:

> FontForge SHOULD NOT, EVER receive untrusted input. Most users only
> use it to edit their own fonts and sometimes popular open-source
> fonts. Even if we fix all the issues findable with automated tools,
> there are many, many memory bugs in FontForge.

Of course, there's the usual question of whether all users and possibly
scripts invoking FontForge are aware of this, but I don't think this is
an unreasonable position for a project to have by itself.

[0] https://github.com/fontforge/fontforge/wiki/Community-guidelines#D1

> Context: ZDI submitted 12 unrelated FontForge CVEs in 2025-12 and
> received the same response
> (https://github.com/fontforge/fontforge/issues/5706).
>
> We post here so distributors and downstream packagers have a public,
> independent record of the FontForge -> FreeType linkage status, and
> can verify their own builds.

> [...]

sam

Download attachment "signature.asc" of type "application/pgp-signature" (419 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.