Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate. | |
| Title | Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openjdk Els |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:openjdk_els:11 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openjdk Els |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-02T10:17:33.209Z
Reserved: 2026-09-22T08:21:58.125Z
Link: CVE-2026-95512
No data.
Status : Received
Published: 2026-10-02T09:16:45.300
Modified: 2026-10-02T09:16:45.300
Link: CVE-2026-95512
No data.
OpenCVE Enrichment
Updated: 2026-10-02T10:30:07Z
-
CWE-400
Uncontrolled Resource Consumption