CVE-2026-34085
published 2026-03-25CVE-2026-34085: fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.6th percentile
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fontconfig | — | — |
| fontconfig_project | fontconfig | < 2.17.1 | 2.17.1 |
| fontconfig_project | fontconfig | — | — |
| fontconfig_project | fontconfig | >= 0 < 2.17.1-3 | 2.17.1-3 |
| msrc | azl3_fontconfig_2.14.2-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_fontconfig_2.13.95-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian5.9LOW
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-34085: (fontconfig before 2
osv·2026-03-26·CVSS 7.8
CVE-2026-34085 [HIGH] CVE-2026-34085: (fontconfig before 2
(fontconfig before 2.17.1 has an off-by-one error in allocation during ...)
GHSA
GHSA-jxv8-p782-98cx: fontconfig before 2
ghsa_unreviewed·2026-03-25
CVE-2026-34085 [MEDIUM] CWE-193 GHSA-jxv8-p782-98cx: fontconfig before 2
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
OSV
CVE-2026-34085: fontconfig before 2
osv·2026-03-25·CVSS 7.8
CVE-2026-34085 [HIGH] CVE-2026-34085: fontconfig before 2
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
Red Hat
fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash
vendor_redhat·2026-03-25·CVSS 5.9
CVE-2026-34085 [MEDIUM] CWE-193 fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash
fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
A flaw was found in fontconfig. This vulnerability, an off-by-one error in how fontconfig handles font capabilities, could allow a local attacker to cause a one-byte out-of-bounds write. This issue may lead to a system crash, resulting in a Denial of Service (DoS), or potentially enable the attacker to execute unauthorized code.
Mitigation: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for
Microsoft
CVE-2026-34085: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
vendor_msrc·2026-03-10·CVSS 5.9
CVE-2026-34085 [MEDIUM] CWE-193 CVE-2026-34085: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Debian
CVE-2026-34085: fontconfig - fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capab...
vendor_debian·2026·CVSS 5.9
CVE-2026-34085 [MEDIUM] CVE-2026-34085: fontconfig - fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capab...
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34085 fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash [fedora-all]
bugzilla·2026-03-26·CVSS 5.9
CVE-2026-34085 [MEDIUM] CVE-2026-34085 fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash [fedora-all]
CVE-2026-34085 fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
The fixed patch has already been backported in 2.17.0-2 (https://src.fedoraproject.org/rpms/fontconfig/c/8bca22ae6843289d280f9d03098bcede86764255?branch=rawhide) and we currently have:
2.16.0-2.fc42 in f42 (not targeted)
2.17.0-3.fc43 in f43 (fixed)
2.17.0-4.fc44 in f44 (fixed)
2.17.0.4.fc44 in rawhide (fixed)
Bugzilla
CVE-2026-34085 fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash
bugzilla·2026-03-25·CVSS 7.8
CVE-2026-34085 [HIGH] CVE-2026-34085 fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash
CVE-2026-34085 fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
Wiz
CVE-2026-34085 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.1
CVE-2026-34085 [MEDIUM] CVE-2026-34085 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34085 :
NixOS vulnerability analysis and mitigation
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
Source : NVD
## 7.8
Score
Published March 25, 2026
Severity HIGH
CNA Score 5.9
Affected Technologies
NixOS
Homebrew
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
fontconfig
fontconfig-devel
Sources
NVD
Homebrew Severity HIGH Has Fix Added at: Mar 29, 2026
Nix Severity HIGH Has Fix Added at: Mar 29, 2026
Red Hat 6, 7
2026-03-25
Published