
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-37011 is a heap corruption vulnerability in GNOME Fonts Viewer (gnome-font-viewer) version 3.34.0 that allows attackers to trigger an out-of-bounds write by supplying a specially crafted TTF font file. The malicious file uses an oversized pattern to cause an infinite malloc() loop, ultimately crashing the gnome-font-viewer process. The vulnerability was formally published on January 29, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is an out-of-bounds write (CWE-787) in gnome-font-viewer's TTF font parsing logic. When processing a TTF file containing an oversized pattern, the application enters an infinite malloc() loop that exhausts heap memory and corrupts it, leading to a denial-of-service crash. Exploitation requires delivering a crafted TTF file to a user who opens it in GNOME Fonts Viewer; a public proof-of-concept exploit is listed on Exploit-DB (EDB-48803) (Exploit-DB, Red Hat Bugzilla).
Successful exploitation results in a denial-of-service condition, crashing the gnome-font-viewer process. There is no evidence of confidentiality or integrity impact under the CVSSv3 assessment — the vulnerability is limited to availability. The scope is confined to the viewer application itself, with no known path to privilege escalation or lateral movement (Red Hat Advisory, Red Hat Bugzilla).
malloc() calls during parsing.malloc() loop, exhausting heap memory and triggering an out-of-bounds write..ttf font files in user download directories or temporary folders.gnome-font-viewer process; crash logs referencing memory allocation failures or heap corruption.journalctl) showing gnome-font-viewer terminating with a segmentation fault or out-of-memory error shortly after opening a TTF file..ttf files via email or web traffic from untrusted or unknown sources.Patches are available for this vulnerability; users should update gnome-font-viewer to a version beyond 3.34.0 as provided by their Linux distribution (Red Hat Bugzilla). As an interim workaround, restrict users from opening TTF font files from untrusted sources and disable automatic font previews where possible. Organizations should also consider implementing file-type filtering at email gateways to block unsolicited font files (Red Hat Advisory).
Red Hat has classified the vulnerability with medium severity and marked it as "Deferred," indicating it is not considered an immediate critical risk in their ecosystem (Red Hat Advisory). A technical write-up was published at infinitsec.net covering the heap corruption mechanics. The CISA vulnerability bulletin for the week of January 26, 2026 referenced this CVE, indicating routine tracking by the U.S. cybersecurity agency (CISA Bulletin). No significant social media controversy or major vendor statements beyond Red Hat's advisory have been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."