CVE-2016-5384: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Fedoraproject Fedora: version 23 only; version 24 only
  • Fontconfig Project Fontconfig: before 2.12.1 (fixed in 2.12.1)

Published 2016-08-13. Last modified 2026-06-17.