Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2230 - Security Advisory
Issued:
2026-02-09
Updated:
2026-02-09

RHSA-2026:2230 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: fontforge security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for fontforge is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FontForge is a font editor for outline and bitmap fonts. It supports a range of font formats, including PostScript (ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts.

Security Fix(es):

  • fontforge: FontForge: Remote Code Execution via heap-based buffer overflow in BMP file parsing (CVE-2025-15279)
  • fontforge: FontForge: Remote Code Execution via Use-After-Free in SFD file parsing (CVE-2025-15269)
  • fontforge: FontForge: Arbitrary code execution via SFD file parsing buffer overflow (CVE-2025-15275)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat CodeReady Linux Builder for x86_64 10 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le
  • Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64

Fixes

  • BZ - 2426421 - CVE-2025-15279 fontforge: FontForge: Remote Code Execution via heap-based buffer overflow in BMP file parsing
  • BZ - 2426423 - CVE-2025-15269 fontforge: FontForge: Remote Code Execution via Use-After-Free in SFD file parsing
  • BZ - 2426429 - CVE-2025-15275 fontforge: FontForge: Arbitrary code execution via SFD file parsing buffer overflow

CVEs

  • CVE-2025-15269
  • CVE-2025-15275
  • CVE-2025-15279

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat CodeReady Linux Builder for x86_64 10

SRPM
fontforge-20230101-14.el10_1.src.rpm SHA-256: cc27ec3a0a5e4848dfb805c10ceff0af7c633bd9871168e47dab88e9d7d00763
x86_64
fontforge-20230101-14.el10_1.x86_64.rpm SHA-256: 2988a70bc24351ad97abd7ee9ab28078d2c3948bd6ebf2c9f699a1f3b9c392be
fontforge-debuginfo-20230101-14.el10_1.x86_64.rpm SHA-256: 29064322a7ea37b45a2ce5c27e6167560f33c3223172682a37af6686a4708ec6
fontforge-debugsource-20230101-14.el10_1.x86_64.rpm SHA-256: d955193f4e671381c840663e87cb681120adc89833868f2c3ef3d0b7286df32f

Red Hat CodeReady Linux Builder for Power, little endian 10

SRPM
fontforge-20230101-14.el10_1.src.rpm SHA-256: cc27ec3a0a5e4848dfb805c10ceff0af7c633bd9871168e47dab88e9d7d00763
ppc64le
fontforge-20230101-14.el10_1.ppc64le.rpm SHA-256: 7aed8ead3bab68bc3ef6325a3222e08e057921375351df564a0dd3c78d498c43
fontforge-debuginfo-20230101-14.el10_1.ppc64le.rpm SHA-256: 31277e02c9842bc01d678899f84bb3c10f5cf07df18612e83acdffe6d207b252
fontforge-debugsource-20230101-14.el10_1.ppc64le.rpm SHA-256: ac24a8121ca276d7557f329055a5b4d7b5371e9a49a8db4431f311874ff1b7e8

Red Hat CodeReady Linux Builder for ARM 64 10

SRPM
fontforge-20230101-14.el10_1.src.rpm SHA-256: cc27ec3a0a5e4848dfb805c10ceff0af7c633bd9871168e47dab88e9d7d00763
aarch64
fontforge-20230101-14.el10_1.aarch64.rpm SHA-256: adc4ec21353b8f35dd447c2a0851a30946027a97c4173087a9d5938e9712576c
fontforge-debuginfo-20230101-14.el10_1.aarch64.rpm SHA-256: 79591920c1d1677cd8f8ab3cb84b31572feac5ceceb72093f12e4393d8db50ed
fontforge-debugsource-20230101-14.el10_1.aarch64.rpm SHA-256: 0b01ff67590c804951325005893ca4f7f9600f5978adf03d65d91c9cce5e11ee

Red Hat CodeReady Linux Builder for IBM z Systems 10

SRPM
fontforge-20230101-14.el10_1.src.rpm SHA-256: cc27ec3a0a5e4848dfb805c10ceff0af7c633bd9871168e47dab88e9d7d00763
s390x
fontforge-20230101-14.el10_1.s390x.rpm SHA-256: e9053fa1ed068a0e4258fbbac01bac010ee555f6af899b3d42cd5538c3260225
fontforge-debuginfo-20230101-14.el10_1.s390x.rpm SHA-256: 4c42fa2bd483e901aa517db520958df07dcb82769bdd68f12a8e56a52ecdf444
fontforge-debugsource-20230101-14.el10_1.s390x.rpm SHA-256: 9afe91c2a5e1ed19dd115d5c3e467104f07dc14b22d3740c244f6d0a6b5b2053

Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2

SRPM
fontforge-20230101-14.el10_1.src.rpm SHA-256: cc27ec3a0a5e4848dfb805c10ceff0af7c633bd9871168e47dab88e9d7d00763
x86_64
fontforge-20230101-14.el10_1.x86_64.rpm SHA-256: 2988a70bc24351ad97abd7ee9ab28078d2c3948bd6ebf2c9f699a1f3b9c392be
fontforge-debuginfo-20230101-14.el10_1.x86_64.rpm SHA-256: 29064322a7ea37b45a2ce5c27e6167560f33c3223172682a37af6686a4708ec6
fontforge-debugsource-20230101-14.el10_1.x86_64.rpm SHA-256: d955193f4e671381c840663e87cb681120adc89833868f2c3ef3d0b7286df32f

Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2

SRPM
fontforge-20230101-14.el10_1.src.rpm SHA-256: cc27ec3a0a5e4848dfb805c10ceff0af7c633bd9871168e47dab88e9d7d00763
ppc64le
fontforge-20230101-14.el10_1.ppc64le.rpm SHA-256: 7aed8ead3bab68bc3ef6325a3222e08e057921375351df564a0dd3c78d498c43
fontforge-debuginfo-20230101-14.el10_1.ppc64le.rpm SHA-256: 31277e02c9842bc01d678899f84bb3c10f5cf07df18612e83acdffe6d207b252
fontforge-debugsource-20230101-14.el10_1.ppc64le.rpm SHA-256: ac24a8121ca276d7557f329055a5b4d7b5371e9a49a8db4431f311874ff1b7e8

Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2

SRPM
fontforge-20230101-14.el10_1.src.rpm SHA-256: cc27ec3a0a5e4848dfb805c10ceff0af7c633bd9871168e47dab88e9d7d00763
s390x
fontforge-20230101-14.el10_1.s390x.rpm SHA-256: e9053fa1ed068a0e4258fbbac01bac010ee555f6af899b3d42cd5538c3260225
fontforge-debuginfo-20230101-14.el10_1.s390x.rpm SHA-256: 4c42fa2bd483e901aa517db520958df07dcb82769bdd68f12a8e56a52ecdf444
fontforge-debugsource-20230101-14.el10_1.s390x.rpm SHA-256: 9afe91c2a5e1ed19dd115d5c3e467104f07dc14b22d3740c244f6d0a6b5b2053

Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2

SRPM
fontforge-20230101-14.el10_1.src.rpm SHA-256: cc27ec3a0a5e4848dfb805c10ceff0af7c633bd9871168e47dab88e9d7d00763
aarch64
fontforge-20230101-14.el10_1.aarch64.rpm SHA-256: adc4ec21353b8f35dd447c2a0851a30946027a97c4173087a9d5938e9712576c
fontforge-debuginfo-20230101-14.el10_1.aarch64.rpm SHA-256: 79591920c1d1677cd8f8ab3cb84b31572feac5ceceb72093f12e4393d8db50ed
fontforge-debugsource-20230101-14.el10_1.aarch64.rpm SHA-256: 0b01ff67590c804951325005893ca4f7f9600f5978adf03d65d91c9cce5e11ee

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility