OSV-2025-550

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/harfbuzz/OSV-2025-550.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2025-550
Published
2025-07-16T00:09:08.050994Z
Modified
2025-07-16T00:09:08.051469Z
Summary
Use-of-uninitialized-value in CFF::cff2_cs_opset_t<cff2_cs_opset_subr_subset_t, CFF::subr_subset_param_t, CFF:
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=431867896

Crash type: Use-of-uninitialized-value
Crash state:
CFF::cff2_cs_opset_t<cff2_cs_opset_subr_subset_t, CFF::subr_subset_param_t, CFF:
cff2_cs_opset_subr_subset_t::process_op
CFF::subr_subsetter_t<cff2_subr_subsetter_t, CFF::Subrs<OT::NumType<true, unsign
References

Affected packages

OSS-Fuzz / harfbuzz

Package

Name
harfbuzz
Purl
pkg:generic/harfbuzz

Affected ranges

Type
GIT
Repo
https://github.com/harfbuzz/harfbuzz.git
Events

Affected versions

11.*
11.1.0
11.2.0
11.2.1
11.3.0
11.3.1
11.3.2
11.3.3

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

introduced_range
"5afbd187b6a05d1764be1fb188e0b9e56dfa7f2c:cf7bffb690efc0d1d9926f8c92620328c4d171b1"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/harfbuzz/OSV-2025-550.yaml"