CVE-2025-15273
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-15273 is a stack-based buffer overflow vulnerability in FontForge that allows remote attackers to execute arbitrary code on affected installations. The flaw exists within the parsing of PFB (Printer Font Binary) files, where user-supplied data length is not properly validated before being copied to a fixed-length stack-based buffer. It affects FontForge version 2025-11-17 and was publicly disclosed on December 29, 2025, as a zero-day advisory after the vendor rejected the report. The vulnerability carries a CVSS v3.0 base score of 8.8 (High) (ZDI Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-121 (Stack-based Buffer Overflow), stemming from the absence of proper length validation of user-supplied data during PFB file parsing before it is copied into a fixed-length stack-based buffer. An attacker exploits this by crafting a malicious PFB file or a web page that triggers FontForge to open such a file, causing a stack buffer overflow that can overwrite control flow data (e.g., return addresses). The precondition for exploitation is user interaction — the target must either visit a malicious page or open a malicious file. ZDI tracked this internally as ZDI-CAN-28546 and published the advisory as a 0-day after the vendor declined to address the report (ZDI Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, potentially leading to full compromise of the affected system's confidentiality, integrity, and availability. An attacker could read sensitive files, modify data, install malware, or use the compromised system as a pivot point for lateral movement within a network. The impact is constrained to the privileges of the user running FontForge, but on systems where FontForge is used in automated font processing pipelines, the blast radius could be broader (ZDI Advisory, Red Hat Bugzilla).

Exploitability

The ZDI published this as a zero-day advisory on December 29, 2025, after the FontForge vendor rejected the vulnerability report and declined to issue a fix. A proof-of-concept exploit reference is available via the ZDI advisory page, though detailed exploit code has not been publicly released. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.353%, reflecting a currently low but non-negligible probability of exploitation (ZDI Advisory).

Exploitation steps

  1. Craft a malicious PFB file: Create a specially crafted Printer Font Binary (PFB) file containing an oversized data segment in the field parsed by FontForge's PFB parser, designed to overflow the fixed-length stack buffer.
  2. Deliver the payload: Host the malicious PFB file on a web server or distribute it via email/file sharing. Alternatively, embed it in a web page that triggers FontForge to open the file automatically (e.g., via a browser plugin or associated file handler).
  3. Trigger user interaction: Socially engineer the target user into visiting the malicious page or opening the malicious PFB file with FontForge.
  4. Overflow the stack buffer: When FontForge parses the PFB file, the lack of length validation causes the oversized data to overflow the stack buffer, overwriting the return address or other control flow data.
  5. Achieve code execution: Control of the instruction pointer allows the attacker to redirect execution to attacker-controlled shellcode or a ROP chain, executing arbitrary code in the context of the current user (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected or newly created PFB files in user download directories, temp folders, or font directories; presence of unknown executables or scripts dropped in user-writable locations after FontForge was opened.
  • Process: FontForge process spawning unexpected child processes (e.g., shells like /bin/bash, cmd.exe, powershell.exe, or network utilities like curl, wget).
  • Network: Outbound connections from the FontForge process or its child processes to unknown external IP addresses or domains, particularly shortly after opening a PFB file.
  • Logs: System or application logs showing FontForge crashes (segmentation faults, access violations) when processing specific PFB files, which may indicate failed exploitation attempts.

Mitigation and workarounds

No official patch has been released by the FontForge vendor, who rejected the vulnerability report submitted by ZDI. The primary recommended mitigation is to restrict interaction with FontForge to only trusted, verified sources and avoid opening PFB files from unknown or untrusted origins. Organizations should consider disabling or restricting FontForge usage in automated pipelines until a fix is available. Users should monitor for a vendor-issued patch and apply it promptly upon release (ZDI Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability received coverage from The Hacker Wire on social media platforms including Mastodon and Bluesky, highlighting the zero-day disclosure and the vendor's rejection of the report. The security community noted concern over the vendor's response — requiring submitters to provide a pull request with a fix rather than acknowledging the vulnerability — which led ZDI to publish the advisory as a 0-day. Red Hat opened a tracking bug (Bug 2426428) indicating downstream Linux distribution awareness and monitoring of the issue (ZDI Advisory, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management