HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade firefox | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade firefox-debugsourceUpgrade firefoxUpgrade firefox-debuginfo | Feb 20, 2026 | Jan 10, 2026 |
| Debian | — | Upgrade harfbuzz | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 10, 2026 |
| Suse | — | Upgrade libharfbuzz-icu0-32bitUpgrade libharfbuzz0-32bitUpgrade libharfbuzz0Upgrade harfbuzz-toolsUpgrade libharfbuzz-gobject0Upgrade libharfbuzz-cairo0Upgrade libharfbuzz-subset0Upgrade typelib-1_0-harfbuzz-0_0Upgrade libharfbuzz-cairo0-32bitUpgrade harfbuzz-develUpgrade libharfbuzz-subset0-32bitUpgrade libharfbuzz-gobject0-32bitUpgrade libharfbuzz-icu0 | Jan 26, 2026 | Jan 26, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 29, 2026 | Jan 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub