Multiple vulnerabilities have been found in FreeType, one of which includes information leak. Affected packages Package media-libs/freetype on all architectures Affected versions < 2.14.3 Unaffected versions >= 2.14.3 Background FreeType is a software font engine that is designed to be small, efficient, highly customizable, and portable while capable of producing high-quality output (glyph images). Description Multiple vulnerabilities have been discovered in FreeType. Please review the CVE identifiers referenced below for details. Impact One of the possible outcomes allows for an out-of-bounds read. Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All FreeType users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/freetype-2.14.3" References CVE-2026-22007 CVE-2026-22008 CVE-2026-22013 CVE-2026-22016 CVE-2026-22018 CVE-2026-22021 CVE-2026-23865 CVE-2026-34268 CVE-2026-34282 Release date August 12, 2026 Latest revision August 12, 2026: 1 Severity normal Exploitable remote Bugzilla entries 970886 971490
Multiple vulnerabilities, including an information leak and an out-of-bounds read, have been discovered in FreeType. The CVSS scores for the referenced CVEs range from Low to Medium, with CVE-2026-22013 rated at 5.3. Affected versions are all releases prior to FreeType 2.14.3, and users must upgrade to version 2.14.3 to remediate, as no workaround is currently available.