CVE-2025-15272
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-15272 is a heap-based buffer overflow vulnerability in FontForge's SFD (Spline Font Database) file parser that allows remote attackers to execute arbitrary code on affected installations. It was discovered and reported to the vendor on December 12, 2025, and publicly disclosed as a 0-day advisory on December 29, 2025, after the FontForge maintainers rejected the vulnerability report. The vulnerability affects FontForge version 2025-11-17 and carries a CVSS v3.0 base score of 8.8 (High) (ZDI Advisory, Red Hat Bugzilla).

Technical details

The root cause is a heap-based buffer overflow (CWE-122) in FontForge's SFD file parsing logic, where user-supplied data length is not properly validated before being copied into a heap-allocated buffer. An attacker can craft a malicious SFD file that triggers this overflow, leading to arbitrary code execution in the context of the current user. Exploitation requires user interaction — the victim must open a malicious SFD file or visit a malicious page that triggers the file to be processed. The vulnerability was tracked internally by ZDI as ZDI-CAN-28547 (ZDI Advisory).

Impact

Successful exploitation results in complete compromise of the affected system in the context of the current user, with high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code, access sensitive data, modify files, or cause a denial of service (system crash). Because FontForge is commonly used in font development workflows, exploitation could expose design assets, credentials stored on the system, or serve as a foothold for lateral movement within a development environment (ZDI Advisory, Red Hat Bugzilla).

Exploitability

A proof-of-concept exploit reference is publicly available via the Zero Day Initiative advisory (ZDI-25-1192), published on December 29, 2025, as a 0-day after the vendor rejected the report. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.35%, reflecting a currently low but non-negligible probability of exploitation given the public PoC availability (ZDI Advisory).

Exploitation steps

  1. Craft a malicious SFD file: Create a specially crafted Spline Font Database (.sfd) file containing oversized or malformed data in a field that FontForge copies into a heap buffer without proper length validation.
  2. Deliver the payload: Host the malicious SFD file on a web page or distribute it via email, file-sharing platforms, or other social engineering channels targeting FontForge users (e.g., font designers, typographers).
  3. Trigger user interaction: Convince the target to open the malicious SFD file directly in FontForge, or visit a malicious web page that initiates the file download and opening.
  4. Trigger heap overflow: When FontForge parses the malicious SFD file, the lack of length validation causes a heap-based buffer overflow, overwriting adjacent heap memory with attacker-controlled data.
  5. Achieve code execution: By carefully controlling the overflow content (e.g., overwriting function pointers or heap metadata), the attacker redirects execution flow to a shellcode or ROP chain, executing arbitrary code as the current user (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected or newly created SFD files in user download directories or temporary folders; unusual executables or scripts dropped in user-writable directories after FontForge is opened.
  • Process: Unexpected child processes spawned by the FontForge process (e.g., sh, bash, cmd.exe, curl, wget, python); FontForge crashing unexpectedly or producing core dumps.
  • Network: Outbound network connections from the FontForge process to unknown external IP addresses or domains, particularly shortly after opening an SFD file.
  • Logs: Application crash logs or core dumps referencing FontForge's SFD parsing routines; OS-level audit logs showing unusual process creation events originating from FontForge.

Mitigation and workarounds

The FontForge maintainers rejected the vulnerability report and have not released an official patch; the only available tracking is a Red Hat Bugzilla entry (Bug 2426427) with no fixed version listed. ZDI's recommended mitigation is to restrict interaction with FontForge and avoid opening SFD files from untrusted or unknown sources. Organizations should consider sandboxing FontForge, implementing application whitelisting, or disabling it in environments where it is not essential until an official fix is available. Monitor the FontForge GitHub repository and Red Hat Bugzilla for community patches or official updates (ZDI Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability was noted on Mastodon (infosec.exchange) and Bluesky by security community accounts shortly after the ZDI advisory was published on December 29, 2025. The Hacker Wire covered the disclosure, highlighting the unusual circumstance of the vulnerability being published as a 0-day after the vendor rejected the report without providing a fix. The vendor's response — requiring reporters to submit pull requests with fixes rather than accepting vulnerability reports — drew criticism from the security community as an atypical and researcher-unfriendly disclosure posture (ZDI Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • cilium-fips-1.20
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • argo-workflows-fips-4.0
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-84640HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management