HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade firefoxUpgrade thunderbird | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade firefoxUpgrade firefox-debugsourceUpgrade firefox-debuginfo | Feb 20, 2026 | Jan 10, 2026 |
| Debian | — | Upgrade harfbuzz | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 10, 2026 |
| Suse | — | Upgrade libharfbuzz0-32bitUpgrade libharfbuzz-icu0-32bitUpgrade libharfbuzz0Upgrade libharfbuzz-subset0Upgrade libharfbuzz-icu0Upgrade harfbuzz-develUpgrade libharfbuzz-gobject0Upgrade libharfbuzz-cairo0Upgrade harfbuzz-toolsUpgrade libharfbuzz-cairo0-32bitUpgrade typelib-1_0-harfbuzz-0_0Upgrade libharfbuzz-subset0-32bitUpgrade libharfbuzz-gobject0-32bit | Jan 26, 2026 | Jan 26, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 29, 2026 | Jan 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub