SUSE-SU-2026:20435-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202620435-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20435-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:20435-1
Upstream
CVE (4)
Related
Published
2026-02-14T21:30:08Z
Modified
2026-03-23T04:52:54Z
Summary
Security update for fontforge
Details

This update for fontforge fixes the following issues:

Update to version 20251009.

Security issues fixed:

  • CVE-2025-15279: remote code execution via heap-based buffer overflow in BMP file parsing (bsc#1256013).
  • CVE-2025-15269: remote code execution via use-after-free in SFD file parsing (bsc#1256032).
  • CVE-2025-15275: arbitrary code execution via SFD file parsing buffer overflow (bsc#1256025).
  • CVE-2025-50949: memory leak in function DlgCreate8 (bsc#1252652).

Other updates and bugfixes:

  • fix multiple crashes in Multiple Masters.

  • fix crash for content over 32767 characters in GDraw multiline text field.

  • fix crash on Up/Down

  • fix crash in Metrics View.

  • fix UFO crash for empty contours.

  • fix crash issue in allmarkglyphs.

  • Version update to 20251009:

    • Update documentation for py scripts (#5180)
    • Update GitHub CI runners (#5328)
    • Update po files from Croudin sources. (#5330)
    • Use consistent Python in MacOS GitHub runner (#5331)
    • Fix CI for Windows GitHub runner (#5335)
    • Fix lookup flags parsing (#5338)
    • Fixes (#5332): glyph file names uXXXXX (#5333)
    • make harmonization robust and avoid zero handles after harmonization (#5262)
    • Quiet strict prototypes warnings. (#5313)
    • Fix crash in parsegvar() due to insufficient buffer (#5339)
    • Handle failed iconv conversion. Unhandled execution path was UB, causing a segfault for me (#5329)
    • Fix CMake function _get_git_version() (#5342)
    • Don't require individual tuple encapsulation in fontforge.font.bitmapSizes setter (#5138)
    • nltransform of anchor points (#5345)
    • Fix generateFontPostHook being called instead of generateFontPreHook (#5226)
    • Always set usDefaultChar to 0 (.notdef) (#5242)
    • add font attributes, method to Python docs (#5353)
    • fix segfault triggered by Python del c[i:j] (#5352)
    • Autoselect internal WOFF2 format (#5346)
    • Fix typos in the FAQ (#5355)
    • add font.style_set_names attribute to Python API (#5354)
    • Bulk tester (#5365)
    • Fix Splinefont shell invocation (#5367)
    • Fix the lists of Windows language IDs (#5359)
    • Support suplementary planes in SFD (emojis etc.) (#5364)
    • Remove psaltnames for multi-code-point names (#5305)
    • doc: added missing sudo to installation instructions (#5300)
    • Fix data corruption on SFD reading (#5380)
    • Compare vertical metrics check when generating TTC (#5372)
    • Treat FT_PIXEL_MODE_MONO as 2 grey levels (#5379)
    • Don't attempt to copy anchors into NULL font (#5405)
    • Fix export of supplementary plane characters in font name to TTF (#5396)
    • Defer crowdin update to the end of the pipeline (#5409)
    • Fix generated feature file bugs (#5384)
    • crowdin: update to java 17 (#5447)
    • Remove assert from Python script processor (#5410)
    • Use sysconfig for Python module locations (#5423)
    • Use PyConfig API on Python 3.8 (#5404)
    • Fix resource leak in unParseTTInstrs (#5476)
    • Only install GUI-specific files if ENABLE_GUI is set (#5451)
    • add math device tables to Python API (#5348)
    • Update CI runner to macOS 13 (#5482)
    • Allow hyphen and special characters in Feature File glyph names (#5358)
    • Fix Python font.appendSFNTName() function (#5494)
    • Update mm.c (#5386)
    • Warning rollup (probably some hidden bugs!) from clang trunk (#5492)
    • Fix function PyFFFont_addSmallCaps. (#5519)
    • Make SmallCaps() create symbols (#5517)
    • Segfault fix and complete implementation of "Don't generate FFTM tables" (#5509)
    • Modernize fixed pitch flag computation (#5506)
    • fix memleak in function utf7toutf8_copy (#5495)
    • Avoid crashes in Python scripts when objects are accessed in invalid state (#5483)
    • Fix CI for Ubuntu 24 (#5531)
    • Bump GitHub CI runner to Ubuntu 22 (#5551)
    • Fix memory corruption in SFUnicodeRanges() (#5537)
    • Add contour draw option to H.Metrics. (#5496)
    • Fix scaling of references in CharView (#5558)
    • Fix TTF validation on load for fixed pitch fonts (#5562)
    • Performance fixes for GSUB/GPOS dumps (#5547)
    • Simple GTK-based dialog with CSS appearance support (#5546)
    • Support Harfbuzz in Metrics View (#5522)
    • Update po files from crowdin translations (#5575)
    • Be more clever about label text in gtextfield (#5583)
    • Add minimal support for GDEF version 1.3 (#5584)
    • Sanitize messages from python (#5589)
    • Fix a crash caused by deleting a glyph with vertical kerning pairs. (#5592)
    • THEME -> GUI_THEME (#5596)
    • Update po translations from Crowdin (#5593)
    • Upgrade to Unicode 16.0.0 (#5594)
    • Fix Linux AppImage (#5599)
    • Upgrade to Unicode 17.0.0 and extend the language and script lists (#5618)
    • Remove X11 and non-Cairo drawing backends (#5612)
    • Add macOS dependency setup script (#5563)
    • Fix hotkeys in BitmapView (#5626)
    • Manually install Inno Setup 6 (#5621)
    • Remove cv->back_img_out_of_date and cv->backimgs (#5625)
    • fix spelling "bt" -> "but" (#5636)
    • Fix typos in Python module docs (#5634)
  • Version update to 20230101+git59.770356c9b:

    • Add contour draw option to H.Metrics. (#5496)
    • Fix memory corruption in SFUnicodeRanges() (#5537)
    • Bump GitHub CI runner to Ubuntu 22 (#5551)
    • Fix CI for Ubuntu 24 (#5531)
    • Avoid crashes in Python scripts when objects are accessed in invalid state (#5483)
    • fix memleak in function utf7toutf8_copy (#5495)
    • Modernize fixed pitch flag computation (#5506)
    • Segfault fix and complete implementation of "Don't generate FFTM tables" (#5509)
    • Make SmallCaps() translate symbols, too. Update documentation accordingly. (#5517)
    • Fix function PyFFFont_addSmallCaps. (#5519)
    • Warning rollup (probably some hidden bugs!) from clang trunk (#5492)
    • Update mm.c (#5386)
    • fix memleak in function DlgCreate8 (#5491)
    • Fix Python font.appendSFNTName() function (#5494)
    • Allow hyphen and special characters in Feature File glyph names (#5358)
    • Update CI runner to macOS 13 (#5482)
    • add math device tables to Python API (#5348)
    • Only install GUI-specific files if ENABLE_GUI is set (#5451)
    • Fix resource leak in unParseTTInstrs (#5476)
    • Use PyConfig API on Python 3.8 (#5404)
    • Use sysconfig for Python module locations (#5423)
    • More crowdin fix
    • Python script shall trigger no asserts (#5410)
    • crowdin: update to java 17 (#5447)
    • try fix crowdin
    • Fix generated feature file bugs (#5384)
    • Defer crowdin update to the end of the pipeline (#5409)
    • Fix export of supplementary plane characters in font name to TTF (#5396)
    • Don't attempt to copy anchors into NULL font (#5405)
    • Treat FT_PIXEL_MODE_MONO as 2 grey levels (#5379)
    • Compare vertical metrics check when generating TTC (#5372)
    • Fix data corruption on SFD reading (#5380)
    • doc: added missing sudo to installation instructions (#5300)
    • Remove psaltnames for multi-code-point names (#5305)
    • Support suplementary planes in SFD (emojis etc.) (#5364)
    • Fix the lists of Windows language IDs (#5359)
    • fix splinefont shell command injection (#5367)
    • Bulk tester (#5365)
    • add font.style_set_names attribute to Python API (#5354)
    • Fix typos in the FAQ (#5355)
    • Autoselect internal WOFF2 format (#5346)
    • fix segfault triggered by Python del c[i:j] (#5352)
    • add font attributes, method to Python docs (#5353)
    • Always set usDefaultChar to 0 (.notdef) (#5242)
    • Fix generateFontPostHook being called instead of generateFontPreHook (#5226)
    • nltransform of anchor points (#5345)
    • Don't require individual tuple encapsulation in fontforge.font.bitmapSizes setter (#5138)
    • Fix CMake function _get_git_version() (#5342)
    • Handle failed iconv conversion. Unhandled execution path was UB, causing a segfault for me (#5329)
    • Fix crash in parsegvar() due to insufficient buffer (#5339)
    • Quiet strict prototypes warnings. (#5313)
    • harmonizing can now no longer produce zero handles, the computation of harmonization is now numerically robust (#5262)
    • Fix glyph file names uXXXXX (#5333)
    • Fix lookup flags parsing (#5338)
    • Duplicate libfontforge.dll for "py" and "pyhook" tests. (#5335)
    • Use consistent Python in MacOS GitHub runner (#5331)
    • Update po files from Croudin sources after fixing problems
    • Fix GinHub CI runners (#5328)
References

Affected packages

SUSE:Linux Enterprise Server 16.0 / fontforge

Package

Name
fontforge
Purl
pkg:rpm/suse/fontforge&distro=SUSE%20Linux%20Enterprise%20Server%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20251009-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "fontforge":  "20251009-160000.1.1",
            "fontforge-devel":  "20251009-160000.1.1",
            "fontforge-doc":  "20251009-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20435-1.json"

SUSE:Linux Enterprise Server for SAP applications 16.0 / fontforge

Package

Name
fontforge
Purl
pkg:rpm/suse/fontforge&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20251009-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "fontforge":  "20251009-160000.1.1",
            "fontforge-devel":  "20251009-160000.1.1",
            "fontforge-doc":  "20251009-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20435-1.json"