CVE-2026-5314

EUVD-2026-18092
A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
VulDBCNA
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 48.79%
Affected Products (NVD)
VendorProductVersion
nothingsstb_truetype.h
𝑥
≤ 1.26
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
nothingsstb
1.0
CNA
nothingsstb
1.1
CNA
nothingsstb
1.2
CNA
nothingsstb
1.3
CNA
nothingsstb
1.4
CNA
nothingsstb
1.5
CNA
nothingsstb
1.6
CNA
nothingsstb
1.7
CNA
nothingsstb
1.8
CNA
nothingsstb
1.9
CNA
nothingsstb
1.10
CNA
nothingsstb
1.11
CNA
nothingsstb
1.12
CNA
nothingsstb
1.13
CNA
nothingsstb
1.14
CNA
nothingsstb
1.15
CNA
nothingsstb
1.16
CNA
nothingsstb
1.17
CNA
nothingsstb
1.18
CNA
nothingsstb
1.19
CNA
nothingsstb
1.20
CNA
nothingsstb
1.21
CNA
nothingsstb
1.22
CNA
nothingsstb
1.23
CNA
nothingsstb
1.24
CNA
nothingsstb
1.25
CNA
nothingsstb
1.26
CNA
Debian logo
Debian Releases
Debian Product
Codename
libstb
bookworm
unimportant
bullseye
unimportant
bullseye (security)
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libstb
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage