Stack-based buffer overflow in HarfBuzz - #VU128344
Published: April 28, 2026
HarfBuzz
Detailed vulnerability description
The vulnerability allows a remote attacker to overwrite other data.
The vulnerability exists due to a stack-based buffer overflow in debug messaging in Sequence.hh when processing a maliciously crafted OpenType font with a GSUB sequence lookup. A remote attacker can supply a crafted font that injects a large number of glyphs to overwrite other data.
The issue is reachable only when debug messaging is enabled using hb_buffer_set_message_func.