Vulnerability Details CVE-2026-34085
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 2.5%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2026-34085
-
cpe:2.3:a:fontconfig_project:fontconfig:2.17.0