CVE-2026-34085 is an off-by-one error in fontconfig before version 2.17.1, specifically within the FcFontCapabilities function, leading to a one-byte out-of-bounds write. This vulnerability affects fontconfig_project fontconfig. Rated High (CVSS 7.8), it has a local attack vector with low attack complexity, requiring low privileges and no user interaction, potentially leading to a crash or high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2.17.1CPE match | cpe:2.3:a:fontconfig_project:fontconfig:*:*:*:*:*:*:*:* | ||
2.17.0CPE matchmatch criteria | cpe:2.3:a:fontconfig_project:fontconfig:2.17.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.