CVE-2025-23022: FreeType

Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

Affected products

Published 2025-01-10. Last modified 2026-06-17.