oss-sec mailing list archives From: Jonathan Wright <jonathan () almalinux org> Date: Wed, 12 Mar 2025 21:15:51 -0500 Thank you for sharing this and for your work on piecing together the commits needed to backport to 2.10.4. On Wed, Mar 12, 2025 at 8:16 PM Michel Lind <michel () michel-slm name> wrote: severity: high (CVSS 3.1: 8.1) Affected versions: <= 2.13.0 Description: An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures...