CVE-2023-25193

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
harfbuzz_projectharfbuzz
𝑥
≤ 6.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
harfbuzz
bullseye
no-dsa
bookworm
no-dsa
buster
no-dsa
trixie
10.1.0-1
fixed
sid
10.1.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
harfbuzz
oracular
not-affected
noble
not-affected
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needed
focal
needed
bionic
needs-triage
xenial
not-affected
trusty
not-affected
openjdk
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
dne
bionic
ignored
xenial
ignored
trusty
ignored
openjdk-13
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
ignored
bionic
dne
xenial
dne
trusty
dne
openjdk-16
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
ignored
bionic
dne
xenial
dne
trusty
dne
openjdk-17
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
Fixed 17.0.8+7-1~23.04
released
jammy
Fixed 17.0.8+7-1~22.04
released
focal
Fixed 17.0.8+7-1~20.04.2
released
bionic
Fixed 17.0.8+7-1~18.04
released
xenial
dne
trusty
dne
openjdk-18
oracular
dne
noble
dne
mantic
dne
lunar
ignored
jammy
ignored
focal
dne
bionic
dne
xenial
dne
trusty
dne
openjdk-19
oracular
dne
noble
dne
mantic
ignored
lunar
ignored
jammy
ignored
focal
dne
bionic
dne
xenial
dne
trusty
dne
openjdk-20
oracular
dne
noble
dne
mantic
not-affected
lunar
Fixed 20.0.2+9+ds1-0ubuntu1~23.04
released
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
openjdk-21
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
Fixed 21.0.1+12-2~23.04
released
jammy
Fixed 21.0.1+12-2~22.04
released
focal
Fixed 21.0.1+12-2~20.04
released
bionic
dne
xenial
dne
trusty
dne
openjdk-22
oracular
needs-triage
mantic
not-affected
lunar
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
openjdk-8
oracular
not-affected
noble
not-affected
mantic
not-affected
lunar
not-affected
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne
openjdk-9
oracular
dne
noble
dne
mantic
dne
lunar
dne
jammy
dne
focal
dne
bionic
dne
xenial
ignored
trusty
dne
openjdk-lts
oracular
Fixed 11.0.20+8-1ubuntu1
released
noble
Fixed 11.0.20+8-1ubuntu1
released
mantic
Fixed 11.0.20+8-1ubuntu1
released
lunar
Fixed 11.0.20+8-1ubuntu1~23.04
released
jammy
Fixed 11.0.20+8-1ubuntu1~22.04
released
focal
Fixed 11.0.20+8-1ubuntu1~20.04
released
bionic
Fixed 11.0.20+8-1ubuntu1~18.04
released
xenial
dne
trusty
dne