Summary: Meta has disclosed a high-severity security vulnerability in the FreeType font rendering library, potentially leading to remote code execution. The CVE identifier assigned is CVE-2025-27363, affecting FreeType versions 2.13.0 and below. Users are urged to update to FreeType 2.13.3 to secure their systems against potential exploits.
Affected: FreeType Library, Various Linux Distributions
Keypoints :
- Vulnerability identified as an out-of-bounds write flaw, with a CVSS score of 8.1.
- Exploits involve parsing specific font files, risking arbitrary code execution.
- Numerous Linux distributions, including Ubuntu and Debian, are affected due to outdated FreeType versions.
- Users should upgrade to FreeType version 2.13.3 for enhanced security.
Source: https://thehackernews.com/2025/03/meta-warns-of-freetype-vulnerability.html