CVE-2026-22693
published 2026-01-10CVE-2026-22693: HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.38%
30.0th percentile
HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | harfbuzz | < harfbuzz 12.3.0-4 (forky) | harfbuzz 12.3.0-4 (forky) |
| debian | libharfbuzz-shaper-perl | — | — |
| harfbuzz | harfbuzz | < 12.3.0 | 12.3.0 |
| harfbuzz_project | harfbuzz | < 12.3.0 | 12.3.0 |
| harfbuzz_project | harfbuzz | >= 0 < 12.3.0-4 | 12.3.0-4 |
| jv | harfbuzz | < 0.032 | 0.032 |
| jv | harfbuzz_shaper | < 0.032 | 0.032 |
| msrc | azl3_harfbuzz_8.3.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_harfbuzz_8.3.0-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_qtbase_6.6.3-4_on_azure_linux_3.0 | — | — |
| msrc | cbl2_harfbuzz_3.4.0-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_qt5-qtbase_5.12.11-19_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv7.5HIGH
vendor_debian7.5LOW
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS
vendor_msrc·2026-01-13·CVSS 5.3
CVE-2026-22693 [MEDIUM] CWE-476 Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS
Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
harfbuzz: Null Pointer Dereference in harfbuzz
vendor_redhat·2026-01-10·CVSS 5.3
CVE-2026-22693 [MEDIUM] CWE-476 harfbuzz: Null Pointer Dereference in harfbuzz
harfbuzz: Null Pointer Dereference in harfbuzz
HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.
A null pointer dereference vector has been discovered in
Debian
CVE-2026-0943: libharfbuzz-shaper-perl - HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with ...
vendor_debian·2026·CVSS 7.5
CVE-2026-0943 [HIGH] CVE-2026-0943: libharfbuzz-shaper-perl - HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with ...
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Scope: local
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2026-22693: harfbuzz - HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer deref...
vendor_debian·2026·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693: harfbuzz - HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer deref...
HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 12.3.0-4)
sid: resolved (fixed in 12
OSV
CVE-2026-0943: HarfBuzz::Shaper versions before 0
osv·2026-01-19·CVSS 7.5
CVE-2026-0943 [HIGH] CVE-2026-0943: HarfBuzz::Shaper versions before 0
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
GHSA
GHSA-hmr2-524c-vv28: HarfBuzz::Shaper versions before 0
ghsa_unreviewed·2026-01-19·CVSS 5.3
CVE-2026-0943 [MEDIUM] CWE-476 GHSA-hmr2-524c-vv28: HarfBuzz::Shaper versions before 0
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.
Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
OSV
CVE-2026-22693: HarfBuzz is a text shaping engine
osv·2026-01-10·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693: HarfBuzz is a text shaping engine
HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0943 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-0943 [HIGH] CVE-2026-0943 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0943 :
Linux Fedora vulnerability analysis and mitigation
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.
Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Source : NVD
## 7.5
Score
Published January 19, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 34.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
perl-HarfBuzz-Shaper
perl-HarfBuzz-Shaper-debuginfo
Sources
NVD
## Get a CVE risk assessment
Get a prioritized vi
Wiz
CVE-2026-22693 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22693 :
NixOS vulnerability analysis and mitigation
HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.
Source : NVD
## 5.3
Score
Publish
Bugzilla
CVE-2026-22693 java-25-openjdk: Null Pointer Dereference in harfbuzz [fedora-42]
bugzilla·2026-01-13·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693 java-25-openjdk: Null Pointer Dereference in harfbuzz [fedora-42]
CVE-2026-22693 java-25-openjdk: Null Pointer Dereference in harfbuzz [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change the 'vers
Bugzilla
CVE-2026-22693 java-latest-openjdk-portable: Null Pointer Dereference in harfbuzz [fedora-42]
bugzilla·2026-01-13·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693 java-latest-openjdk-portable: Null Pointer Dereference in harfbuzz [fedora-42]
CVE-2026-22693 java-latest-openjdk-portable: Null Pointer Dereference in harfbuzz [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, cha
Bugzilla
CVE-2026-22693 ghc-gi-harfbuzz: Null Pointer Dereference in harfbuzz [fedora-43]
bugzilla·2026-01-13·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693 ghc-gi-harfbuzz: Null Pointer Dereference in harfbuzz [fedora-43]
CVE-2026-22693 ghc-gi-harfbuzz: Null Pointer Dereference in harfbuzz [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
gi-harfbuzz is a binding layer over the harfbuzz shared library.
So it is not directly affected.
Bugzilla
CVE-2026-22693 java-latest-openjdk: Null Pointer Dereference in harfbuzz [fedora-42]
bugzilla·2026-01-13·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693 java-latest-openjdk: Null Pointer Dereference in harfbuzz [fedora-42]
CVE-2026-22693 java-latest-openjdk: Null Pointer Dereference in harfbuzz [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change the '
Bugzilla
CVE-2026-22693 ghc-gi-harfbuzz: Null Pointer Dereference in harfbuzz [epel-10]
bugzilla·2026-01-13·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693 ghc-gi-harfbuzz: Null Pointer Dereference in harfbuzz [epel-10]
CVE-2026-22693 ghc-gi-harfbuzz: Null Pointer Dereference in harfbuzz [epel-10]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
gi-harfbuzz is a binding layer over the harfbuzz shared library.
So it is not directly affected.
Bugzilla
CVE-2026-22693 perl-HarfBuzz-Shaper: Null Pointer Dereference in harfbuzz [fedora-42]
bugzilla·2026-01-13·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693 perl-HarfBuzz-Shaper: Null Pointer Dereference in harfbuzz [fedora-42]
CVE-2026-22693 perl-HarfBuzz-Shaper: Null Pointer Dereference in harfbuzz [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change the
Bugzilla
CVE-2026-22693 java-21-openjdk-portable: Null Pointer Dereference in harfbuzz [fedora-42]
bugzilla·2026-01-13·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693 java-21-openjdk-portable: Null Pointer Dereference in harfbuzz [fedora-42]
CVE-2026-22693 java-21-openjdk-portable: Null Pointer Dereference in harfbuzz [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change
Bugzilla
CVE-2026-22693 java-21-openjdk: Null Pointer Dereference in harfbuzz [fedora-42]
bugzilla·2026-01-13·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693 java-21-openjdk: Null Pointer Dereference in harfbuzz [fedora-42]
CVE-2026-22693 java-21-openjdk: Null Pointer Dereference in harfbuzz [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change the 'vers
Bugzilla
CVE-2026-22693 harfbuzz: Null Pointer Dereference in harfbuzz
bugzilla·2026-01-10·CVSS 5.3
CVE-2026-22693 [MEDIUM] CVE-2026-22693 harfbuzz: Null Pointer Dereference in harfbuzz
CVE-2026-22693 harfbuzz: Null Pointer Dereference in harfbuzz
HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.
Discussion:
Well there is no information
2026-01-10
Published