Out-of-bounds write in FreeType - CVE-2025-27363
Published: March 14, 2025 / Updated: August 29, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input. A remote attacker can pass a specially crafted font to the application that is using an affected version of the library, trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
Oracle Linux
Debian Linux
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
SUSE Enterprise Storage
OpenBSD
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Slackware Linux
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Google Android
Storage Virtualize vSphere Remote Plug-in
Rapid Infrastructure Automation
Security QRadar EDR
Oracle Communications Operations Monitor
IBM Enterprise Content Management Text Search
IBM Security Directory Suite
Maximo Application Suite - Visual Inspection Component
Cognos Transformer
Financial Reporting
Cognos PowerPlay
Oracle Communications Policy Management
Business Automation Insights
APEX Cloud Platform for Microsoft Azure
Cloud Kubernetes Service
IBM Watson Machine Learning Accelerator
DataStage on Cloud Pak for Data
Red Hat OpenShift on IBM Cloud
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Db2 Big SQL
SmartFabric OS10
System Storage DS8900F
Netcool Operations Insight
IBM OmniFind Text Search Server for DB2 for i
WebSphere Automation
IBM Cloud Pak for Security
IBM Cloud Pak for Data System
IBM Security Verify Governance
IBM Power Hardware Management Console (HMC)
IBM Netezza Performance Server
Primavera P6 Enterprise Project Portfolio Management
IBM Automation Decision Services
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Network Analytics Data Director
APEX Cloud Platform for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
IBM Sterling Partner Engagement Manager
Session Smart Router
App Connect Enterprise Certified Container
QRadar Suite
watsonx.data
Communications Unified Assurance
IBM Qradar SIEM
Oracle Outside In Technology
RSA Authentication Manager
SmartFabric Manager
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libfreetype6 (Ubuntu package)
libfreetype6
libfreetype6-32bit
libfreetype6-debuginfo
libfreetype6-debuginfo-32bit
freetype2-devel
ft2demos
freetype2-debugsource
mingw32-freetype
mingw32-freetype-static
mingw64-freetype-static
mingw64-freetype
freetype-devel
freetype
freetype-demos
freetype (Red Hat package)
freetype2-profile-tti35
ftinspect
ftstring
ftgamma
ftdiff
ftmulti
ftvalid
ftview
ftdump
ftbench
ftlint
ftgrid
libfreetype6-32bit-debuginfo
freetype2-devel-32bit
freetype (Debian package)
freetype-help
freetype-debuginfo
freetype-debugsource
media-libs/freetype
freetype2
spice-client-win (Red Hat package)
spice-client-win-x64
spice-client-win-x86
JD Edwards EnterpriseOne Tools
Primavera Unifier
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
IBM API Connect
IBM Cognos Analytics
Oracle Documaker
Oracle AutoVue
IBM App Connect Enterprise
Oracle Database Server
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Policy
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM FileNet Content Manager
IBM DS8000 Hardware Management Console
How to mitigate CVE-2025-27363
Storage Virtualize vSphere Remote Plug-in - update to 2.0.0.2
Rapid Infrastructure Automation - update to 1.1.5.3
Netcool Operations Insight - update to 1.6.15
WebSphere Automation - update to 1.8.2
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
watsonx.data - update to 2.2
Security QRadar EDR - update to 3.12.17
IBM Security Directory Suite - update to 8.0.1.24
IBM Qradar SIEM - update to 7.5.0 Update Pack 11 IF04
RSA Authentication Manager - update to 8.8 Patch 1
Maximo Application Suite - Visual Inspection Component - update to 9.0.9
IBM Security Verify Governance - update to 10.0.2.0.7
IBM API Connect - update to 10.0.8.2 ifix2
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP3, 10.3.1060.0 SP2
Cognos Transformer - addressed in versions 11.2.4 IF5, 12.0.4 IF3, 12.1.0 iF1
IBM Cognos Analytics - addressed in versions 11.2.4 IF7, 12.0.4 IF3, 12.1.0 IF1
IBM Netezza Performance Server - update to 11.2.3.5
IBM App Connect Enterprise - update to 12.0.12.3
Cognos PowerPlay - update to 12.1.0 IF1
Oracle Database Server - addressed in versions 19.28, 21.19, 23.9.0
Primavera P6 Enterprise Project Portfolio Management - update to 20.12.21.1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF005, 24.0.1-IF002
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF005, 24.0.1-IF002
Business Automation Insights - update to 24.0.1.0.4
libfreetype6 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.10.1-2ubuntu0.4, 2.11.1+dfsg-1ubuntu0.3
Red Hat OpenShift Serverless - update to 1
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - addressed in versions 01.04.01.00, 01.05.01.00
Migration Toolkit for Containers - update to 1.8.7
Cloud Kubernetes Service - addressed in versions 1.28.15 1601_W, 1.29.15 1582_W, 1.30.11 1560_W, 1.31.7 1544_W
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
libfreetype6 - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
libfreetype6-32bit - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
libfreetype6-debuginfo - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
libfreetype6-debuginfo-32bit - update to 2.6.3-7.21.1
freetype2-devel - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
ft2demos - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
freetype2-debugsource - addressed in versions 2.6.3-7.21.1, 2.10.4-150000.4.18.1
mingw32-freetype - update to 2.8-3
mingw32-freetype-static - update to 2.8-3
mingw64-freetype-static - update to 2.8-3
mingw64-freetype - update to 2.8-3
freetype-devel - addressed in versions 2.8-15, 2.10.4-10
freetype - addressed in versions 2.8-15, 2.10.4-10
freetype-demos - update to 2.8-15
freetype (Red Hat package) - addressed in versions 2.9.1-6.el8_6.3, 2.9.1-7.el8_4, 2.9.1-10.el8_8, 2.9.1-10.el8_10, 2.10.4-10.el9_2
freetype2-profile-tti35 - update to 2.10.4-150000.4.18.1
ftinspect - update to 2.10.4-150000.4.18.1
ftstring - update to 2.10.4-150000.4.18.1
ftgamma - update to 2.10.4-150000.4.18.1
ftdiff - update to 2.10.4-150000.4.18.1
ftmulti - update to 2.10.4-150000.4.18.1
ftvalid - update to 2.10.4-150000.4.18.1
ftview - update to 2.10.4-150000.4.18.1
ftdump - update to 2.10.4-150000.4.18.1
ftbench - update to 2.10.4-150000.4.18.1
ftlint - update to 2.10.4-150000.4.18.1
ftgrid - update to 2.10.4-150000.4.18.1
libfreetype6-32bit-debuginfo - update to 2.10.4-150000.4.18.1
freetype2-devel-32bit - update to 2.10.4-150000.4.18.1
freetype (Debian package) - update to 2.12.1+dfsg-5+deb12u4
freetype - update to 2.12.1-4
freetype-help - update to 2.12.1-4
freetype-devel - update to 2.12.1-4
freetype-demos - update to 2.12.1-4
freetype-debuginfo - update to 2.12.1-4
freetype-debugsource - update to 2.12.1-4
media-libs/freetype - update to 2.13.1
freetype - update to 2.13.3
freetype2 - update to 2.13.3-3
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Red Hat OpenShift Dev Spaces - update to 3.20.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4
IBM Watson Machine Learning Accelerator - addressed in versions 4.8.6.1, 5.0.2.1
DataStage on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
Red Hat OpenShift on IBM Cloud - addressed in versions 4.12.74 1631, 4.13.56 1614, 4.14.49 1604, 4.15.48 1581, 4.16.38 1562, 4.17.23 1535
Red Hat OpenShift Container Platform - addressed in versions 4.12.75, 4.12.76, 4.14.50, 4.15.49, 4.16.39, 4.17.24, 4.18.8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.3
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1
watsonx Assistant Cartridge - update to 5.2.1
IBM FileNet Content Manager - addressed in versions 5.5.12.0 IF007, 5.6.0.0 IF006, 5.7.0.0 IF003
OpenShift Logging - update to 5.8.20
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.3.1, 6.2.4.0.1
Session Smart Router - addressed in versions 6.2.10, 6.3.7
Db2 Big SQL - update to 8.2
spice-client-win (Red Hat package) - addressed in versions 8.2-1.el8_2, 8.4-2.el8_4, 8.6-1.el8_6, 8.8-5.el8_8, 8.10-1.el8_10
spice-client-win-x64 - update to 8.10-1
spice-client-win-x86 - update to 8.10-1
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9, 10.6.0.3
IBM DS8000 Hardware Management Console - update to 10.10.106.0 R10.1
App Connect Enterprise Certified Container - addressed in versions 12.0.11, 12.11.0
Google Android - addressed in versions 13 2025-05-01, 14 2025-05-01
System Storage DS8900F - update to 89.44.4.0 R9.4 SP4
Links to Public Exploits and PoC-codes
External References
- http://www.openwall.com/lists/oss-security/2025/03/13/1
- http://www.openwall.com/lists/oss-security/2025/03/13/11
- http://www.openwall.com/lists/oss-security/2025/03/13/12
- http://www.openwall.com/lists/oss-security/2025/03/13/2
- http://www.openwall.com/lists/oss-security/2025/03/13/3
- http://www.openwall.com/lists/oss-security/2025/03/13/8
- https://www.facebook.com/security/advisories/cve-2025-27363
Related Security Bulletins
- Remote code execution in FreeType
- Slackware Linux update for freetype
- Ubuntu update for freetype
- Debian update for freetype
- Ubuntu update for freetype
- SUSE update for freetype2
- openEuler update for freetype
- OpenBSD update for FreeType
- SUSE update for freetype2
- Red Hat Enterprise Linux 8 update for freetype
- Red Hat Enterprise Linux 9 update for freetype
- Red Hat Enterprise Linux 8 update for freetype
- Red Hat Enterprise Linux 8 update for freetype
- Red Hat Enterprise Linux 8 update for freetype
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12 packages
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.20
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Oracle Outside In Technology
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Anolis OS update for freetype
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in IBM QRadar SIEM
- IBM App Connect Enterprise update for FreeType
- IBM Cognos Transformer update for FreeType
- IBM Cognos Analytics update for FreeType
- IBM Cognos PowerPlay update for FreeType
- IBM WebSphere Automation update for FreeType
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- IBM Watson Speech Services Cartridge update for FreeType
- IBM Maximo Application Suite - Visual Inspection Component update for FreeType
- IBM Business Automation Workflow update for FreeType
- Multiple vulnerabilities in Google Android
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- IBM Watson Machine Learning Accelerator on Cloud Pak for Data update for FreeType
- IBM Storage Virtualize vSphere Remote Plug-in update for FreeType
- IBM DataStage on Cloud Pak for Data update for FreeType
- IBM Cloud Pak for Business Automation update for FreeType
- Red Hat OpenShift on IBM Cloud update for FreeType
- IBM Cloud Kubernetes Service update for FreeType
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Gentoo update for FreeType
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Dell SmartFabric OS10
- Arch Linux update for freetype2
- Dell SmartFabric OS10 update for third-party components
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in IBM Security QRadar EDR
- Dell Networking OS10 update for third-party components
- IBM Cloud Pak for Data System 2.0 update for FreeType
- Red Hat Enterprise Linux 8 update for mingw-freetype and spice-client-win
- Red Hat Enterprise Linux 8 update for spice-client-win
- Red Hat Enterprise Linux 8 update for spice-client-win
- IBM Netezza Performance Server update for FreeType
- Multiple vulnerabilities in IBM Rapid Infrastructure Automation
- Red Hat Enterprise Linux 8 update for mingw-freetype and spice-client-win
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Anolis OS update for spice-client-win and mingw-freetype
- Multiple vulnerabilities in IBM Cloud Pak for Security and IBM QRadar Suite Software
- Dell SmartFabric Manager update for third-party components
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in IBM API Connect
- IBM watsonx.data update for FreeType
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Red Hat Enterprise Linux 8 update for spice-client-win
- IBM Power Hardware Management Console (HMC) update for FreeType
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Oracle Communications Policy Management
- Multiple vulnerabilities in Oracle Communications Network Analytics Data Director
- Multiple vulnerabilities in Oracle Communications Operations Monitor
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function
- Multiple vulnerabilities in IBM Business Automation Insights
- Anolis OS update for freetype
- IBM Sterling Partner Engagement Manager update for FreeType
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for FreeType
- Multiple vulnerabilities in IBM DS8900F and DS8A00 Hardware Management Console (HMC)
- Multiple vulnerabilities in IBM Security Directory Suite
- Out-of-bounds write in Primavera P6 Enterprise Project Portfolio Management
- Multiple vulnerabilities in Primavera Unifier
- Multiple vulnerabilities in Oracle Documaker
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in Financial Reporting
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in Oracle AutoVue
- Multiple vulnerabilities in Oracle Database Server
- IBM Db2 Big SQL on Cloud Pak for Data update for FreeType
- Juniper Session Smart Router update for third-party components
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM FileNet Content Manager (FNCM) Content Based Retrieval (CBR)
- Multiple vulnerabilities in IBM OmniFind Text Search Server for DB2 for i