ELA-1368-1 freetype security update

out-of-bounds write

2025-04-01
Packagefreetype
Version2.6.3-3.2+deb9u4 (stretch), 2.9.1-3+deb10u4 (buster)
Related CVEs CVE-2025-27363


An out of bounds write with subglyph structures has been fixed in the font rendering library FreeType.



For Debian 10 buster, these problems have been fixed in version 2.9.1-3+deb10u4.

For Debian 9 stretch, these problems have been fixed in version 2.6.3-3.2+deb9u4.

We recommend that you upgrade your freetype packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.