CVE-2025-15276
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-15276 is a deserialization of untrusted data vulnerability in FontForge's SFD (Spline Font Database) file parser that allows remote attackers to execute arbitrary code. The flaw affects FontForge version 20251009 and was publicly disclosed on December 29, 2025, as a zero-day advisory by the Zero Day Initiative after the vendor rejected the vulnerability report. It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper validation of user-supplied data during SFD file parsing, classified as CWE-502 (Deserialization of Untrusted Data). When FontForge processes a maliciously crafted SFD file, it deserializes attacker-controlled data without adequate sanitization, enabling arbitrary code execution in the context of the current process. Exploitation requires user interaction — the target must open a malicious SFD file or visit a malicious page that triggers FontForge file processing. The vulnerability was internally tracked as ZDI-CAN-28198 and credited to researcher volticks (@movx64) (ZDI Advisory).

Impact

Successful exploitation grants an attacker arbitrary code execution in the context of the FontForge process, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker could read sensitive files accessible to the user running FontForge, modify or destroy data, and potentially use the compromised host as a pivot point for lateral movement within a network. The attack vector is local (the file must be opened by the victim), but the vulnerability is classified as remotely exploitable because an attacker can deliver the malicious SFD file via email, web download, or a malicious webpage (ZDI Advisory, Red Hat Bugzilla).

Exploitability

The vulnerability was published as a zero-day advisory on December 29, 2025, after the vendor rejected the fix request, meaning no patch was available at the time of disclosure. A proof-of-concept exploit reference exists via the ZDI advisory, though no evidence of active in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.22%, indicating a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (ZDI Advisory).

Exploitation steps

  1. Craft a malicious SFD file: Create a specially crafted Spline Font Database (.sfd) file containing a malicious serialized payload that exploits the lack of input validation in FontForge's SFD parser.
  2. Deliver the payload: Distribute the malicious SFD file to the target via email attachment, file-sharing platform, or by hosting it on a malicious webpage that triggers automatic download or processing.
  3. Induce user interaction: Social-engineer the target into opening the malicious SFD file with FontForge, or visit a page that causes FontForge to process the file (e.g., via a browser plugin or file association).
  4. Trigger deserialization: When FontForge parses the SFD file, the malicious serialized data is processed without proper validation, triggering deserialization of attacker-controlled objects.
  5. Achieve code execution: The deserialization process executes arbitrary code in the context of the FontForge process, granting the attacker the same privileges as the user running FontForge (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected .sfd files in user download directories, temporary folders, or email attachment staging areas; new or modified files in user home directories created by the FontForge process shortly after opening an SFD file.
  • Process: Unusual child processes spawned by the FontForge process (e.g., shell interpreters like /bin/bash, cmd.exe, curl, wget, or network utilities); FontForge process making unexpected outbound network connections.
  • Network: Outbound connections from the FontForge process or its child processes to unknown external IP addresses or domains, particularly shortly after a user opens an SFD file.
  • Logs: System or application logs showing FontForge crashing or producing unexpected errors during SFD file parsing; audit logs recording unusual file access or process creation events originating from the FontForge process (ZDI Advisory).

Mitigation and workarounds

No vendor-released patch is currently available; the FontForge maintainers rejected the vulnerability report, stating only pull requests with required fixes would be considered. The primary mitigation recommended by ZDI is to restrict user interaction with FontForge — specifically, avoid opening SFD files from untrusted or unknown sources. Organizations should consider uninstalling FontForge on systems where it is not essential, implement application whitelisting to limit FontForge execution on critical systems, and monitor vendor repositories for community-contributed fixes. Users should also disable any file associations that automatically open SFD files with FontForge (ZDI Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability generated notable attention on social media platforms including Mastodon, Bluesky, and Infosec.Exchange, primarily driven by the unusual circumstance of it being published as a zero-day due to vendor rejection. Security community commentary highlighted the vendor's stance — requiring submitters to provide pull requests with fixes rather than accepting vulnerability reports — as a problematic disclosure policy. Red Hat tracked the issue in their Bugzilla system with high severity, and Tenable published a detection plugin (Nessus plugin 281469). The disclosure was covered by TheHackerWire and aggregated by multiple vulnerability intelligence platforms (ZDI Advisory, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-branding-upstream
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management