NULL pointer dereference in HarfBuzz - CVE-2026-22693

 

NULL pointer dereference in HarfBuzz - CVE-2026-22693

Published: April 28, 2026


Vulnerability identifier: #VU128345
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-22693
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in OT::SubtableUnicodesCache::create() when processing font subsetting operations. A remote attacker can trigger a memory allocation failure that leads to a null pointer being used with placement new to cause a denial of service.

The issue is triggered when hb_malloc returns NULL, such as in low-memory conditions or with custom allocators that simulate allocation failures, and results in a segmentation fault during hb_subset_preprocess.


Affected software

HarfBuzz
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
openSUSE Leap
Anolis OS
openEuler
harfbuzz-debuginfo
harfbuzz
harfbuzz-help
harfbuzz-devel
harfbuzz-debugsource
libharfbuzz0-32bit
libharfbuzz-gobject0-32bit
libharfbuzz-subset0-32bit
libharfbuzz-subset0-32bit-debuginfo
libharfbuzz-icu0-32bit
libharfbuzz-cairo0-32bit-debuginfo
libharfbuzz0-32bit-debuginfo
libharfbuzz-icu0-64bit
libharfbuzz-subset0-debuginfo
libharfbuzz-gobject0-64bit-debuginfo
libharfbuzz-icu0-64bit-debuginfo
libharfbuzz-subset0-64bit
libharfbuzz-cairo0-64bit
libharfbuzz0-64bit
libharfbuzz0-64bit-debuginfo
libharfbuzz-gobject0-64bit
libharfbuzz-cairo0-64bit-debuginfo
libharfbuzz-subset0-64bit-debuginfo
libharfbuzz-icu0-32bit-debuginfo
libharfbuzz-gobject0-debuginfo
libharfbuzz-subset0
harfbuzz-tools-debuginfo
libharfbuzz-gobject0
libharfbuzz-icu0-debuginfo
typelib-1_0-HarfBuzz-0_0
libharfbuzz-icu0
libharfbuzz0
libharfbuzz-cairo0-debuginfo
harfbuzz-tools
libharfbuzz0-debuginfo
libharfbuzz-cairo0
libharfbuzz-cairo0-32bit
libharfbuzz-gobject0-32bit-debuginfo
harfbuzz-icu
harfbuzz-doc

How to mitigate CVE-2026-22693

Install security update from vendor's website.

HarfBuzz - update to 12.3.0
harfbuzz-debuginfo - update to 8.3.0-4
harfbuzz - update to 8.3.0-4
harfbuzz-help - update to 8.3.0-4
harfbuzz-devel - update to 8.3.0-4
harfbuzz-debugsource - update to 8.3.0-4
libharfbuzz0-32bit - update to 8.3.0-150600.3.3.1
libharfbuzz-gobject0-32bit - update to 8.3.0-150600.3.3.1
libharfbuzz-subset0-32bit - update to 8.3.0-150600.3.3.1
libharfbuzz-subset0-32bit-debuginfo - update to 8.3.0-150600.3.3.1
libharfbuzz-icu0-32bit - update to 8.3.0-150600.3.3.1
libharfbuzz-cairo0-32bit-debuginfo - update to 8.3.0-150600.3.3.1
libharfbuzz0-32bit-debuginfo - update to 8.3.0-150600.3.3.1
libharfbuzz-icu0-64bit - update to 8.3.0-150600.3.3.1
libharfbuzz-subset0-debuginfo - update to 8.3.0-150600.3.3.1
libharfbuzz-gobject0-64bit-debuginfo - update to 8.3.0-150600.3.3.1
libharfbuzz-icu0-64bit-debuginfo - update to 8.3.0-150600.3.3.1
libharfbuzz-subset0-64bit - update to 8.3.0-150600.3.3.1
libharfbuzz-cairo0-64bit - update to 8.3.0-150600.3.3.1
libharfbuzz0-64bit - update to 8.3.0-150600.3.3.1
libharfbuzz0-64bit-debuginfo - update to 8.3.0-150600.3.3.1
libharfbuzz-gobject0-64bit - update to 8.3.0-150600.3.3.1
libharfbuzz-cairo0-64bit-debuginfo - update to 8.3.0-150600.3.3.1
libharfbuzz-subset0-64bit-debuginfo - update to 8.3.0-150600.3.3.1
libharfbuzz-icu0-32bit-debuginfo - update to 8.3.0-150600.3.3.1
harfbuzz-devel - update to 8.3.0-150600.3.3.1
libharfbuzz-gobject0-debuginfo - update to 8.3.0-150600.3.3.1
libharfbuzz-subset0 - update to 8.3.0-150600.3.3.1
harfbuzz-tools-debuginfo - update to 8.3.0-150600.3.3.1
harfbuzz-debugsource - update to 8.3.0-150600.3.3.1
libharfbuzz-gobject0 - update to 8.3.0-150600.3.3.1
libharfbuzz-icu0-debuginfo - update to 8.3.0-150600.3.3.1
typelib-1_0-HarfBuzz-0_0 - update to 8.3.0-150600.3.3.1
libharfbuzz-icu0 - update to 8.3.0-150600.3.3.1
libharfbuzz0 - update to 8.3.0-150600.3.3.1
libharfbuzz-cairo0-debuginfo - update to 8.3.0-150600.3.3.1
harfbuzz-tools - update to 8.3.0-150600.3.3.1
libharfbuzz0-debuginfo - update to 8.3.0-150600.3.3.1
libharfbuzz-cairo0 - update to 8.3.0-150600.3.3.1
libharfbuzz-cairo0-32bit - update to 8.3.0-150600.3.3.1
libharfbuzz-gobject0-32bit-debuginfo - update to 8.3.0-150600.3.3.1
harfbuzz - update to 8.4.0-2
harfbuzz-devel - update to 8.4.0-2
harfbuzz-icu - update to 8.4.0-2
harfbuzz-doc - update to 8.4.0-2

External References

Related Security Bulletins