Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2025-175

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via con...

JLSEC Published
Modified
Affected Packages
HarfBuzz_jll < 8.3.1+0
HarfBuzz_ICU_jll < 8.5.0+0
Aliases / Upstream
CVE-2023-25193

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

References