Fontconfig is a font configuration and customization library widely embedded in Linux distributions and graphical applications, where its vulnerability exposure concentrates in memory-management operations reflected in weakness classes such as double-free conditions and off-by-one errors. These are characteristic flaws in low-level font parsing and caching logic that can affect any downstream application that links the library. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fontconfig Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5384HIGH fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code | Aug 13, 2016 | 7.8 | 28 | NO | NO |
CVE-2026-34085HIGH fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution | Mar 25, 2026 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fontconfig Project.
Media articles that mention a CVE ID that affects a product developed by Fontconfig Project — matched by CVE ID, not by vendor name.