Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2232 - Security Advisory
Issued:
2026-02-09
Updated:
2026-02-09

RHSA-2026:2232 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: fontforge security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for fontforge is now available for Red Hat Enterprise Linux 10.0 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FontForge is a font editor for outline and bitmap fonts. It supports a range of font formats, including PostScript (ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts.

Security Fix(es):

  • fontforge: FontForge: Remote Code Execution via heap-based buffer overflow in BMP file parsing (CVE-2025-15279)
  • fontforge: FontForge: Remote Code Execution via Use-After-Free in SFD file parsing (CVE-2025-15269)
  • fontforge: FontForge: Arbitrary code execution via SFD file parsing buffer overflow (CVE-2025-15275)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.0 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.0 ppc64le
  • Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.0 s390x
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.0 aarch64

Fixes

  • BZ - 2426421 - CVE-2025-15279 fontforge: FontForge: Remote Code Execution via heap-based buffer overflow in BMP file parsing
  • BZ - 2426423 - CVE-2025-15269 fontforge: FontForge: Remote Code Execution via Use-After-Free in SFD file parsing
  • BZ - 2426429 - CVE-2025-15275 fontforge: FontForge: Arbitrary code execution via SFD file parsing buffer overflow

CVEs

  • CVE-2025-15269
  • CVE-2025-15275
  • CVE-2025-15279

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.0

SRPM
fontforge-20230101-14.el10_0.src.rpm SHA-256: 5a3236abd69715989c87e3175656f64f016df3ebf6b4add6e077ac82f673a0c5
x86_64
fontforge-20230101-14.el10_0.x86_64.rpm SHA-256: dee5826ed7b31774a68fe7766e4655b0761dd481c4540f8b74dfd111e39b558a
fontforge-debuginfo-20230101-14.el10_0.x86_64.rpm SHA-256: 3dbad6c5e0a3861875e44522a07bd82073c04a44db75cb39ccbb1bec72b2ac8b
fontforge-debugsource-20230101-14.el10_0.x86_64.rpm SHA-256: faac6aa59720f756d3d2854a16339aaa787e8dbda272eeca9f56606ee384d731

Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.0

SRPM
fontforge-20230101-14.el10_0.src.rpm SHA-256: 5a3236abd69715989c87e3175656f64f016df3ebf6b4add6e077ac82f673a0c5
ppc64le
fontforge-20230101-14.el10_0.ppc64le.rpm SHA-256: d55160d64575f4ae4b65097442a9d2e30ff4e99374ea932be6aa4fd7a0da0c59
fontforge-debuginfo-20230101-14.el10_0.ppc64le.rpm SHA-256: 2802cc589f03975c1664015d03c36e75711e0f95434bead96ef1564db740c8b7
fontforge-debugsource-20230101-14.el10_0.ppc64le.rpm SHA-256: 227f8c1931151cb6ffaa2d453ad814cd35f69bf2cfd11e204d4f2a3495210d4d

Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.0

SRPM
fontforge-20230101-14.el10_0.src.rpm SHA-256: 5a3236abd69715989c87e3175656f64f016df3ebf6b4add6e077ac82f673a0c5
s390x
fontforge-20230101-14.el10_0.s390x.rpm SHA-256: cf0b648f5279a1242257c48c9d87032bc3a1e023666fd2f092f948c07669fc06
fontforge-debuginfo-20230101-14.el10_0.s390x.rpm SHA-256: 47e70a8c505f03e6a6f0f6ba0bbf7e86eeef9bb5b4a03275bc1ac5fc355368b3
fontforge-debugsource-20230101-14.el10_0.s390x.rpm SHA-256: c6491c79480205c30266212645e5c1ce8e9f38b60d6df65f3f2f22baa7374168

Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.0

SRPM
fontforge-20230101-14.el10_0.src.rpm SHA-256: 5a3236abd69715989c87e3175656f64f016df3ebf6b4add6e077ac82f673a0c5
aarch64
fontforge-20230101-14.el10_0.aarch64.rpm SHA-256: fb559059535b3a3ca1cca1364ee87437eb4abd3caf041acd81d02b37e412ec74
fontforge-debuginfo-20230101-14.el10_0.aarch64.rpm SHA-256: 7fa6a408476977e84fa5a5a1e6b592e8ea9c793ac982107ae7110d5c085e0c0d
fontforge-debugsource-20230101-14.el10_0.aarch64.rpm SHA-256: a00abd3d1282b6043b578a2c3a33594a158e8db688c2062fe84cec8f35a8ebec

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility