[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2026-50811/freetype

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 24 13:40:07 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d66bd124 by Salvatore Bonaccorso at 2026-07-24T14:37:22+02:00
Track fixed version for CVE-2026-50811/freetype

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15593,7 +15593,7 @@ CVE-2026-53479 (DellPowerProtectData Domain, versions 7.7.1.0 through 8.7, LTS20
 CVE-2026-51937 (An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitiv ...)
 	NOT-FOR-US: Oneblog
 CVE-2026-50811 (An out-of-bounds read vulnerability exists in FreeType 2.14.3 and vers ...)
-	- freetype <unfixed> (bug #1141704)
+	- freetype 2.14.3+dfsg-2 (bug #1141704)
 	[trixie] - freetype <not-affected> (Vulnerable code introduced later)
 	[bookworm] - freetype <not-affected> (TT_Get_Var_Design OOB read introduced in 2.14.0; shipped code uses safe coords[i]=0)
 	[bullseye] - freetype <not-affected> (TT_Get_Var_Design OOB read introduced in 2.14.0; shipped code uses safe coords[i]=0)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d66bd124638c1be45a80dba74af7e7a1117124ec

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d66bd124638c1be45a80dba74af7e7a1117124ec
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/35ff4c0c/attachment.htm>


More information about the debian-security-tracker-commits mailing list