CVE-2023-25193

Source
https://cve.org/CVERecord?id=CVE-2023-25193
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25193.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-25193
Aliases
Downstream
AZL (1)
BELL (1)
CGA (8)
CLSA (5)
DEBIAN (1)
ECHO (1)
JLSEC (1)
MGASA (1)
MINI (8)
OESA (2)
openSUSE (6)
RHSA (15)
RLSA (2)
ROOT (2)
SUSE (9)
UBUNTU (1)
Related
Published
2023-02-04T00:00:00Z
Modified
2026-08-12T13:32:34Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

Database specific
{
    "cna_assigner":  "mitre",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25193.json"
}
References

Affected packages

Git / github.com/harfbuzz/harfbuzz

Affected ranges

Type
GIT
Repo
https://github.com/harfbuzz/harfbuzz
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:harfbuzz_project:harfbuzz:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "6.0.0"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.6.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8
1.9.0
2.*
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.*
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.3.0
3.3.1
3.3.2
3.4.0
4.*
4.0.0
4.0.1
4.1.0
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
5.*
5.0.0
5.0.1
5.1.0
5.2.0
5.3.0
5.3.1
6.*
6.0.0
Other
hb-rename
ng-mergepoint
pango-extractpoint
pango-start

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25193.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "199082770400909606321589194843450527664",
                "87419159144381551629992409665691100659",
                "316516650934869293814167978590599149972",
                "203275194265138133167303134542089474071"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2023-25193-cb610f4e",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc",
        "target":  {
            "file":  "src/hb-ot-layout-gsubgpos.hh"
        }
    }
]
vanir_signatures_modified
"2026-08-12T13:32:34Z"