Out-of-bounds write in FreeType - CVE-2025-27363

 

Out-of-bounds write in FreeType - CVE-2025-27363

Published: March 14, 2025 / Updated: August 29, 2025


Vulnerability identifier: #VU105715
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-27363
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input. A remote attacker can pass a specially crafted font to the application that is using an affected version of the library, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

FreeType
Oracle Linux
Debian Linux
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
SUSE Enterprise Storage
OpenBSD
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Slackware Linux
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Google Android
Storage Virtualize vSphere Remote Plug-in
Rapid Infrastructure Automation
Security QRadar EDR
Oracle Communications Operations Monitor
IBM Enterprise Content Management Text Search
IBM Security Directory Suite
Maximo Application Suite - Visual Inspection Component
Cognos Transformer
Financial Reporting
Cognos PowerPlay
Oracle Communications Policy Management
Business Automation Insights
APEX Cloud Platform for Microsoft Azure
Cloud Kubernetes Service
IBM Watson Machine Learning Accelerator
DataStage on Cloud Pak for Data
Red Hat OpenShift on IBM Cloud
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Db2 Big SQL
SmartFabric OS10
System Storage DS8900F
Netcool Operations Insight
IBM OmniFind Text Search Server for DB2 for i
WebSphere Automation
IBM Cloud Pak for Security
IBM Cloud Pak for Data System
IBM Security Verify Governance
IBM Power Hardware Management Console (HMC)
IBM Netezza Performance Server
Primavera P6 Enterprise Project Portfolio Management
IBM Automation Decision Services
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Network Analytics Data Director
APEX Cloud Platform for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
IBM Sterling Partner Engagement Manager
Session Smart Router
App Connect Enterprise Certified Container
QRadar Suite
watsonx.data
Communications Unified Assurance
IBM Qradar SIEM
Oracle Outside In Technology
RSA Authentication Manager
SmartFabric Manager
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libfreetype6 (Ubuntu package)
libfreetype6
libfreetype6-32bit
libfreetype6-debuginfo
libfreetype6-debuginfo-32bit
freetype2-devel
ft2demos
freetype2-debugsource
mingw32-freetype
mingw32-freetype-static
mingw64-freetype-static
mingw64-freetype
freetype-devel
freetype
freetype-demos
freetype (Red Hat package)
freetype2-profile-tti35
ftinspect
ftstring
ftgamma
ftdiff
ftmulti
ftvalid
ftview
ftdump
ftbench
ftlint
ftgrid
libfreetype6-32bit-debuginfo
freetype2-devel-32bit
freetype (Debian package)
freetype-help
freetype-debuginfo
freetype-debugsource
media-libs/freetype
freetype2
spice-client-win (Red Hat package)
spice-client-win-x64
spice-client-win-x86
JD Edwards EnterpriseOne Tools
Primavera Unifier
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
IBM API Connect
IBM Cognos Analytics
Oracle Documaker
Oracle AutoVue
IBM App Connect Enterprise
Oracle Database Server
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Policy
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM FileNet Content Manager
IBM DS8000 Hardware Management Console

How to mitigate CVE-2025-27363

Install updates from vendor's website.

FreeType - update to 2.13.1
Storage Virtualize vSphere Remote Plug-in - update to 2.0.0.2
Rapid Infrastructure Automation - update to 1.1.5.3
Netcool Operations Insight - update to 1.6.15
WebSphere Automation - update to 1.8.2
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
watsonx.data - update to 2.2
Security QRadar EDR - update to 3.12.17
IBM Security Directory Suite - update to 8.0.1.24
IBM Qradar SIEM - update to 7.5.0 Update Pack 11 IF04
RSA Authentication Manager - update to 8.8 Patch 1
Maximo Application Suite - Visual Inspection Component - update to 9.0.9
IBM Security Verify Governance - update to 10.0.2.0.7
IBM API Connect - update to 10.0.8.2 ifix2
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP3, 10.3.1060.0 SP2
Cognos Transformer - addressed in versions 11.2.4 IF5, 12.0.4 IF3, 12.1.0 iF1
IBM Cognos Analytics - addressed in versions 11.2.4 IF7, 12.0.4 IF3, 12.1.0 IF1
IBM Netezza Performance Server - update to 11.2.3.5
IBM App Connect Enterprise - update to 12.0.12.3
Cognos PowerPlay - update to 12.1.0 IF1
Oracle Database Server - addressed in versions 19.28, 21.19, 23.9.0
Primavera P6 Enterprise Project Portfolio Management - update to 20.12.21.1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF005, 24.0.1-IF002
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF005, 24.0.1-IF002
Business Automation Insights - update to 24.0.1.0.4
libfreetype6 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.10.1-2ubuntu0.4, 2.11.1+dfsg-1ubuntu0.3
Red Hat OpenShift Serverless - update to 1
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - addressed in versions 01.04.01.00, 01.05.01.00
Migration Toolkit for Containers - update to 1.8.7
Cloud Kubernetes Service - addressed in versions 1.28.15 1601_W, 1.29.15 1582_W, 1.30.11 1560_W, 1.31.7 1544_W
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
libfreetype6 - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
libfreetype6-32bit - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
libfreetype6-debuginfo - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
libfreetype6-debuginfo-32bit - update to 2.6.3-7.21.1
freetype2-devel - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
ft2demos - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
freetype2-debugsource - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
mingw32-freetype - update to 2.8-3
mingw32-freetype-static - update to 2.8-3
mingw64-freetype-static - update to 2.8-3
mingw64-freetype - update to 2.8-3
freetype-devel - addressed in versions 2.8-15, 2.10.4-10
freetype - addressed in versions 2.8-15, 2.10.4-10
freetype-demos - update to 2.8-15
freetype (Red Hat package) - addressed in versions 2.9.1-6.el8_6.3, 2.9.1-7.el8_4, 2.9.1-10.el8_8, 2.9.1-10.el8_10, 2.10.4-10.el9_2
freetype2-profile-tti35 - update to 2.10.4-150000.4.18.1
ftinspect - update to 2.10.4-150000.4.18.1
ftstring - update to 2.10.4-150000.4.18.1
ftgamma - update to 2.10.4-150000.4.18.1
ftdiff - update to 2.10.4-150000.4.18.1
ftmulti - update to 2.10.4-150000.4.18.1
ftvalid - update to 2.10.4-150000.4.18.1
ftview - update to 2.10.4-150000.4.18.1
ftdump - update to 2.10.4-150000.4.18.1
ftbench - update to 2.10.4-150000.4.18.1
ftlint - update to 2.10.4-150000.4.18.1
ftgrid - update to 2.10.4-150000.4.18.1
libfreetype6-32bit-debuginfo - update to 2.10.4-150000.4.18.1
freetype2-devel-32bit - update to 2.10.4-150000.4.18.1
freetype (Debian package) - update to 2.12.1+dfsg-5+deb12u4
freetype - update to 2.12.1-4
freetype-help - update to 2.12.1-4
freetype-devel - update to 2.12.1-4
freetype-demos - update to 2.12.1-4
freetype-debuginfo - update to 2.12.1-4
freetype-debugsource - update to 2.12.1-4
media-libs/freetype - update to 2.13.1
freetype - update to 2.13.3
freetype2 - update to 2.13.3-3
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Red Hat OpenShift Dev Spaces - update to 3.20.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4
IBM Watson Machine Learning Accelerator - addressed in versions 4.8.6.1, 5.0.2.1
DataStage on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
Red Hat OpenShift on IBM Cloud - addressed in versions 4.12.74 1631, 4.13.56 1614, 4.14.49 1604, 4.15.48 1581, 4.16.38 1562, 4.17.23 1535
Red Hat OpenShift Container Platform - addressed in versions 4.12.75, 4.12.76, 4.14.50, 4.15.49, 4.16.39, 4.17.24, 4.18.8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.3
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1
watsonx Assistant Cartridge - update to 5.2.1
IBM FileNet Content Manager - addressed in versions 5.5.12.0 IF007, 5.6.0.0 IF006, 5.7.0.0 IF003
OpenShift Logging - update to 5.8.20
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.3.1, 6.2.4.0.1
Session Smart Router - addressed in versions 6.2.10, 6.3.7
Db2 Big SQL - update to 8.2
spice-client-win (Red Hat package) - addressed in versions 8.2-1.el8_2, 8.4-2.el8_4, 8.6-1.el8_6, 8.8-5.el8_8, 8.10-1.el8_10
spice-client-win-x64 - update to 8.10-1
spice-client-win-x86 - update to 8.10-1
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9, 10.6.0.3
IBM DS8000 Hardware Management Console - update to 10.10.106.0 R10.1
App Connect Enterprise Certified Container - addressed in versions 12.0.11, 12.11.0
Google Android - addressed in versions 13 2025-05-01, 14 2025-05-01
System Storage DS8900F - update to 89.44.4.0 R9.4 SP4

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins