GHSA-5r97-79vw-qvm4

Suggest an improvement
Source
https://github.com/advisories/GHSA-5r97-79vw-qvm4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5r97-79vw-qvm4/GHSA-5r97-79vw-qvm4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5r97-79vw-qvm4
Published
2026-05-18T15:38:59Z
Modified
2026-05-18T15:49:42Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Microsoft DirectX12: .spritefont multiply overflow only in 32-bit builds
Details

Impact

The spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.

This impacts the use of the DirectX Tool Kit SpriteFont class file loading ctor if given untrusted data files.

Note this only applies to x86/ARM builds of the library. ARM64 and x64 native is not subject to this issue.

Patches

This bug has been fixed in the May 7, 2026 release. Alternatively, you can just update your copy of the reader as per this commit.

Workarounds

This does not apply if a project's .spritefont files are all 'trusted' data that were included with an application. It's primarily an issue only if developers are using user-provided or network downloaded spritefont files.

Database specific
{
    "cwe_ids":  [
        "CWE-190"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-18T15:38:59Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

NuGet / directxtk12_desktop_win10

Package

Name
directxtk12_desktop_win10
View open source insights on deps.dev
Purl
pkg:nuget/directxtk12_desktop_win10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.5.8.1

Affected versions

2025.*
2025.3.21.3
2025.7.10.1
2025.10.28.1
2026.*
2026.4.1.1

Database specific

last_known_affected_version_range
"< 2026.4.1.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5r97-79vw-qvm4/GHSA-5r97-79vw-qvm4.json"

NuGet / directxtk12_uwp

Package

Name
directxtk12_uwp
View open source insights on deps.dev
Purl
pkg:nuget/directxtk12_uwp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.5.8.1

Affected versions

2016.*
2016.6.30.1
2016.7.18.1
2016.8.4.1
2016.9.1.1
2016.9.15.1
2016.10.6.1
2016.12.5.1
2017.*
2017.2.10.1
2017.4.24.1
2017.6.21.1
2017.9.22.1
2017.12.13.1
2018.*
2018.4.23.1
2018.5.14.1
2018.6.1.2
2018.7.3.1
2018.8.18.2
2018.9.13.1
2018.10.26.1
2018.10.31.1
2018.11.20.1
2019.*
2019.2.7.1
2019.4.26.1
2019.5.31.1
2019.8.23.1
2019.10.17.1
2019.12.17.1
2020.*
2020.2.24.1
2020.5.11.1
2020.6.2.1
2020.6.15.1
2020.7.2.1
2020.8.15.1
2020.9.30.1
2020.11.12.1
2021.*
2021.1.10.1
2021.4.7.2
2021.6.10.2
2021.8.2.1
2021.10.1.1
2021.10.15.1
2021.10.19.1
2021.11.8.1
2022.*
2022.3.1.1
2022.3.24.1
2022.5.10.1
2022.7.30.1
2022.10.18.1
2022.12.18.1
2023.*
2023.2.7.1
2023.3.30.1
2023.4.28.1
2023.9.6.2
2023.10.31.1
2024.*
2024.1.1.1
2024.2.22.1
2024.6.5.1
2024.9.5.1
2024.10.29.1
2025.*
2025.3.21.3
2025.7.10.1
2025.10.28.1
2026.*
2026.4.1.1

Database specific

last_known_affected_version_range
"< 2026.4.1.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5r97-79vw-qvm4/GHSA-5r97-79vw-qvm4.json"