CVE-2020-37011
Linux Ubuntu vulnerability analysis and mitigation

Overview

CVE-2020-37011 is a heap corruption vulnerability in GNOME Fonts Viewer (gnome-font-viewer) version 3.34.0 that allows attackers to trigger an out-of-bounds write by supplying a specially crafted TTF font file. The malicious file uses an oversized pattern to cause an infinite malloc() loop, ultimately crashing the gnome-font-viewer process. The vulnerability was formally published on January 29, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is an out-of-bounds write (CWE-787) in gnome-font-viewer's TTF font parsing logic. When processing a TTF file containing an oversized pattern, the application enters an infinite malloc() loop that exhausts heap memory and corrupts it, leading to a denial-of-service crash. Exploitation requires delivering a crafted TTF file to a user who opens it in GNOME Fonts Viewer; a public proof-of-concept exploit is listed on Exploit-DB (EDB-48803) (Exploit-DB, Red Hat Bugzilla).

Impact

Successful exploitation results in a denial-of-service condition, crashing the gnome-font-viewer process. There is no evidence of confidentiality or integrity impact under the CVSSv3 assessment — the vulnerability is limited to availability. The scope is confined to the viewer application itself, with no known path to privilege escalation or lateral movement (Red Hat Advisory, Red Hat Bugzilla).

Exploitation steps

  1. Craft malicious TTF file: Using the public PoC (EDB-48803), generate a TTF font file containing an oversized pattern in a font table field that triggers repeated malloc() calls during parsing.
  2. Deliver the file: Send the crafted TTF file to a target user via email attachment, file share, or web download, relying on social engineering to prompt the user to open it.
  3. Trigger parsing: The victim opens the TTF file with GNOME Fonts Viewer (gnome-font-viewer 3.34.0), which begins parsing the font file.
  4. Heap exhaustion: The oversized pattern causes the application to enter an infinite malloc() loop, exhausting heap memory and triggering an out-of-bounds write.
  5. Crash: The gnome-font-viewer process crashes, achieving a denial-of-service condition (Exploit-DB, Red Hat Bugzilla).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .ttf font files in user download directories or temporary folders.
  • Process: Repeated crashes or core dumps of the gnome-font-viewer process; crash logs referencing memory allocation failures or heap corruption.
  • Logs: System journal entries (journalctl) showing gnome-font-viewer terminating with a segmentation fault or out-of-memory error shortly after opening a TTF file.
  • Network: Unusual inbound delivery of .ttf files via email or web traffic from untrusted or unknown sources.

Mitigation and workarounds

Patches are available for this vulnerability; users should update gnome-font-viewer to a version beyond 3.34.0 as provided by their Linux distribution (Red Hat Bugzilla). As an interim workaround, restrict users from opening TTF font files from untrusted sources and disable automatic font previews where possible. Organizations should also consider implementing file-type filtering at email gateways to block unsolicited font files (Red Hat Advisory).

Community reactions

Red Hat has classified the vulnerability with medium severity and marked it as "Deferred," indicating it is not considered an immediate critical risk in their ecosystem (Red Hat Advisory). A technical write-up was published at infinitsec.net covering the heap corruption mechanics. The CISA vulnerability bulletin for the week of January 26, 2026 referenced this CVE, indicating routine tracking by the U.S. cybersecurity agency (CISA Bulletin). No significant social media controversy or major vendor statements beyond Red Hat's advisory have been observed.

Additional resources


SourceThis report was generated using AI

Related Linux Ubuntu vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-50737CRITICAL9
  • Linux Debian logoLinux Debian
  • pglogical
NoNoJul 28, 2026
CVE-2026-50736CRITICAL9
  • Linux Debian logoLinux Debian
  • pglogical
NoNoJul 28, 2026
CVE-2026-50738HIGH7.7
  • Linux Debian logoLinux Debian
  • pglogical
NoNoJul 28, 2026
CVE-2026-61547NONEN/A
  • Linux Debian logoLinux Debian
  • librabbitmq
NoYesJul 29, 2026
CVE-2026-59986NONEN/A
  • Linux Debian logoLinux Debian
  • librabbitmq
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management