CVE-2025-27363

high KEV
Published 2025-03-31 · Modified 2025-04-01
CVSS v3
CVSS v2
VIR risk
9.5

Description

Important: freetype security update

CISA KEV

Vendor
FreeType
Product
FreeType
Due date
2025-05-27

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2025-3421.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2025:3421

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2025-8292.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2359357

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2359355

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2359354

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2359353

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2359342

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2359341

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2357070

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2357069

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2357067

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2351357

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2025:8292

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://source.android.com/docs/security/bulletin/2025-05-01 ; https://nvd.nist.gov/vuln/detail/CVE-2025-27363

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:3407

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-27363.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-27363

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:3421

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:8292

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202505-11

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2025:3407

Exploits

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
arch archfixed2.13.3-3
debian debianbookwormfixed2.12.1+dfsg-5+deb12u4
debian debianbullseyefixed2.10.4+dfsg-1+deb11u2
debian debianforkyfixed2.13.1+dfsg-1
debian debiansidfixed2.13.1+dfsg-1
debian debiantrixiefixed2.13.1+dfsg-1
suse slesaffected
rockylinux rocky9fixed

References

Verify integrity in audit chain (admin only). AS-IS.