cbcvebase.
CVE-2023-25193
published 2023-02-04

CVE-2023-25193: hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base…

PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.81%
76.2th percentile
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianharfbuzz< harfbuzz 8.0.0-1 (forky)harfbuzz 8.0.0-1 (forky)
fedoraprojectfedora
harfbuzz_projectharfbuzz<= 6.0.0
harfbuzz_projectharfbuzz>= 0 < 8.0.0-18.0.0-1
harfbuzz_projectharfbuzz>= 0 < 8.0.0-18.0.0-1
msrcazl3_mozjs_102.15.1-1_on_azure_linux_3.0
msrccbl2_harfbuzz_3.4.0-3_on_cbl_mariner_2.0
msrccbl2_qt5-qtbase_5.12.11-15_on_cbl_mariner_2.0
msrccm1_harfbuzz_3.4.0-1_on_cbl_mariner_1.0
msrccm1_mozjs60_60.9.0-13_on_cbl_mariner_1.0
msrccm1_qt5-qtbase_5.12.11-7_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_oracle3.7HIGH
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.