
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15272 is a heap-based buffer overflow vulnerability in FontForge's SFD (Spline Font Database) file parser that allows remote attackers to execute arbitrary code on affected installations. It was discovered and reported to the vendor on December 12, 2025, and publicly disclosed as a 0-day advisory on December 29, 2025, after the FontForge maintainers rejected the vulnerability report. The vulnerability affects FontForge version 2025-11-17 and carries a CVSS v3.0 base score of 8.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The root cause is a heap-based buffer overflow (CWE-122) in FontForge's SFD file parsing logic, where user-supplied data length is not properly validated before being copied into a heap-allocated buffer. An attacker can craft a malicious SFD file that triggers this overflow, leading to arbitrary code execution in the context of the current user. Exploitation requires user interaction — the victim must open a malicious SFD file or visit a malicious page that triggers the file to be processed. The vulnerability was tracked internally by ZDI as ZDI-CAN-28547 (ZDI Advisory).
Successful exploitation results in complete compromise of the affected system in the context of the current user, with high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code, access sensitive data, modify files, or cause a denial of service (system crash). Because FontForge is commonly used in font development workflows, exploitation could expose design assets, credentials stored on the system, or serve as a foothold for lateral movement within a development environment (ZDI Advisory, Red Hat Bugzilla).
A proof-of-concept exploit reference is publicly available via the Zero Day Initiative advisory (ZDI-25-1192), published on December 29, 2025, as a 0-day after the vendor rejected the report. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.35%, reflecting a currently low but non-negligible probability of exploitation given the public PoC availability (ZDI Advisory).
sh, bash, cmd.exe, curl, wget, python); FontForge crashing unexpectedly or producing core dumps.The FontForge maintainers rejected the vulnerability report and have not released an official patch; the only available tracking is a Red Hat Bugzilla entry (Bug 2426427) with no fixed version listed. ZDI's recommended mitigation is to restrict interaction with FontForge and avoid opening SFD files from untrusted or unknown sources. Organizations should consider sandboxing FontForge, implementing application whitelisting, or disabling it in environments where it is not essential until an official fix is available. Monitor the FontForge GitHub repository and Red Hat Bugzilla for community patches or official updates (ZDI Advisory, Red Hat Bugzilla).
The vulnerability was noted on Mastodon (infosec.exchange) and Bluesky by security community accounts shortly after the ZDI advisory was published on December 29, 2025. The Hacker Wire covered the disclosure, highlighting the unusual circumstance of the vulnerability being published as a 0-day after the vendor rejected the report without providing a fix. The vendor's response — requiring reporters to submit pull requests with fixes rather than accepting vulnerability reports — drew criticism from the security community as an atypical and researcher-unfriendly disclosure posture (ZDI Advisory).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
fontforge
devel
fontforge
focal (esm-apps)
fontforge
jammy
fontforge
jammy (esm-apps)
fontforge
noble
fontforge
noble (esm-apps)
fontforge
resolute
fontforge
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."