Gentoo 2532 Published by

Gentoo Linux released security advisory GLSA 202608-02 to patch multiple vulnerabilities in media-libs/freetype for versions below 2.14.3. The flaws encompass an out-of-bounds read and information disclosure risk across nine CVE identifiers, with no known workaround available. Administrators must update the font engine to version 2.14.3 or later to resolve the issues. Install the fix by running emerge --sync and then emerge --ask --oneshot --verbose ">=media-libs/freetype-2.14.3".

[ GLSA 202608-02 ] FreeType: Multiple Vulnerabilities




[ GLSA 202608-02 ] FreeType: Multiple Vulnerabilities


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202608-02
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: FreeType: Multiple Vulnerabilities
Date: August 12, 2026
Bugs: #970886, #971490
ID: 202608-02

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in FreeType, one of which
includes information leak.

Background
==========

FreeType is a software font engine that is designed to be small,
efficient, highly customizable, and portable while capable of producing
high-quality output (glyph images).

Affected packages
=================

Package Vulnerable Unaffected
------------------- ------------ ------------
media-libs/freetype < 2.14.3 >= 2.14.3

Description
===========

Multiple vulnerabilities have been discovered in FreeType. Please review
the CVE identifiers referenced below for details.

Impact
======

One of the possible outcomes allows for an out-of-bounds read. Please
review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All FreeType users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/freetype-2.14.3"

References
==========

[ 1 ] CVE-2026-22007
https://nvd.nist.gov/vuln/detail/CVE-2026-22007
[ 2 ] CVE-2026-22008
https://nvd.nist.gov/vuln/detail/CVE-2026-22008
[ 3 ] CVE-2026-22013
https://nvd.nist.gov/vuln/detail/CVE-2026-22013
[ 4 ] CVE-2026-22016
https://nvd.nist.gov/vuln/detail/CVE-2026-22016
[ 5 ] CVE-2026-22018
https://nvd.nist.gov/vuln/detail/CVE-2026-22018
[ 6 ] CVE-2026-22021
https://nvd.nist.gov/vuln/detail/CVE-2026-22021
[ 7 ] CVE-2026-23865
https://nvd.nist.gov/vuln/detail/CVE-2026-23865
[ 8 ] CVE-2026-34268
https://nvd.nist.gov/vuln/detail/CVE-2026-34268
[ 9 ] CVE-2026-34282
https://nvd.nist.gov/vuln/detail/CVE-2026-34282

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/202608-02

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.