CVE-2025-15274
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-15274 is a heap-based buffer overflow vulnerability in FontForge's SFD file parser that allows remote attackers to execute arbitrary code on affected installations. The flaw was discovered and reported to the vendor on December 12, 2025, and publicly disclosed as a zero-day advisory on December 29, 2025, after the vendor rejected the report. It affects FontForge version 2025-11-17 and carries a CVSS v3.0 base score of 8.8 (High) (ZDI Advisory, Red Hat Bugzilla).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and stems from insufficient validation of the length of user-supplied data before it is copied into a heap-based buffer during the parsing of SFD (Spline Font Database) files. An attacker can craft a malicious SFD file or host it on a web page to trigger the overflow when the victim opens the file or visits the page. Exploitation requires user interaction but no special privileges, making it accessible to unauthenticated remote attackers (ZDI Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code in the context of the current user running FontForge, resulting in high confidentiality, integrity, and availability impact. An attacker who achieves code execution could access sensitive files, modify data, or disrupt the application. While the scope is limited to the current user's privileges, this could serve as a foothold for further lateral movement in environments where FontForge is used in automated font processing pipelines (ZDI Advisory).

Exploitability

The vulnerability was published as a zero-day advisory on December 29, 2025, after the FontForge vendor rejected the report, meaning no official patch was available at the time of disclosure. A proof-of-concept is referenced in the ZDI advisory (ZDI-CAN-28544), though no evidence of active in-the-wild exploitation has been reported. The EPSS score is approximately 0.35%, indicating a currently low probability of widespread exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (ZDI Advisory).

Exploitation steps

  1. Craft a malicious SFD file: Create a specially crafted SFD (Spline Font Database) file containing oversized or malformed data in a field that is copied to a heap buffer without length validation during parsing.
  2. Deliver the payload: Host the malicious SFD file on a web page or distribute it via email/file sharing, relying on social engineering to convince the target user to open it with FontForge.
  3. Trigger the overflow: When the victim opens the malicious SFD file in FontForge, the parser copies the oversized user-supplied data into a fixed-size heap buffer, causing a heap-based buffer overflow.
  4. Achieve code execution: By carefully controlling the overflow data (e.g., overwriting heap metadata or function pointers), the attacker redirects execution flow to attacker-controlled shellcode or a ROP chain, executing arbitrary code with the privileges of the current user (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected or unusually large SFD files opened by FontForge; new or modified files in user home directories or temp folders created around the time FontForge was run.
  • Process: Unusual child processes spawned by the FontForge process (e.g., sh, bash, curl, wget, python) that are not part of normal FontForge operation.
  • Network: Unexpected outbound network connections originating from the FontForge process to unknown external IP addresses, potentially indicating a reverse shell or data exfiltration attempt.
  • Logs: System or application logs showing FontForge crashes (segmentation faults, heap corruption errors) that may indicate failed or probing exploitation attempts.

Mitigation and workarounds

The FontForge vendor rejected the vulnerability report, and no official patch was available at the time of public disclosure on December 29, 2025. ZDI's recommended mitigation is to restrict user interaction with FontForge and avoid opening SFD files from untrusted sources. Organizations should isolate FontForge installations in sandboxed or restricted environments, disable FontForge access where not strictly necessary, and monitor the FontForge GitHub repository and Red Hat Bugzilla (Bug 2426435) for any upstream fixes or patched releases (ZDI Advisory, Red Hat Bugzilla).

Community reactions

The Zero Day Initiative published the advisory as a 0-day after the vendor rejected the report, noting that FontForge stated only pull requests including required fixes would be considered — an unusual response that drew attention to the vendor's patch process. The vulnerability was picked up by several security aggregators and community platforms including The Hacker Wire, VulDB, and CIRCL's vulnerability lookup service shortly after disclosure. Red Hat opened a tracking bug (Bug 2426435) indicating downstream Linux distribution interest in monitoring the issue for potential impact on packaged versions of FontForge (ZDI Advisory, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management