CVE-2025-15277
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-15277 is a heap-based buffer overflow vulnerability in FontForge's SGI file parser that allows remote attackers to execute arbitrary code on affected installations. The flaw exists within the parsing of scanlines in SGI image files, where user-supplied data length is not properly validated before being copied to a heap-based buffer. It affects FontForge version 20251009 and was publicly disclosed on December 29, 2025, as a zero-day advisory after the vendor rejected the vulnerability report. The CVSS v3.0 base score is 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and resides in the GUtils component responsible for parsing SGI image file scanlines. The root cause is the absence of proper length validation of user-supplied data before it is copied into a heap-allocated buffer, enabling a classic heap overflow condition. Exploitation requires user interaction — specifically, the target must open a malicious SGI file or visit a malicious page that triggers the file parsing. The vulnerability was discovered by researcher volticks (@movx64) and tracked internally by ZDI as ZDI-CAN-27920 (ZDI Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the FontForge process, potentially leading to full compromise of confidentiality, integrity, and availability on the affected system. Since FontForge typically runs with user-level privileges, an attacker could access files and data accessible to that user, install malware, or pivot to further attacks within the environment. The attack vector is local (the malicious file must be opened), but delivery can be achieved remotely by tricking a user into opening a crafted SGI file (ZDI Advisory, Red Hat Bugzilla).

Exploitability

A proof-of-concept exploit is publicly available via the Zero Day Initiative advisory, published on December 29, 2025, as a 0-day after the vendor rejected the vulnerability report. There is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.042%, indicating a low but non-zero probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (ZDI Advisory).

Exploitation steps

  1. Craft a malicious SGI file: Create a specially crafted SGI image file with a manipulated scanline length field that exceeds the bounds of the heap-allocated buffer in FontForge's GUtils parser.
  2. Deliver the payload: Distribute the malicious SGI file via email attachment, file-sharing platform, or embed it in a web page that triggers automatic file opening (e.g., via a browser plugin or associated application).
  3. Induce user interaction: Social-engineer the target into opening the malicious file with FontForge, or visiting a malicious web page that causes FontForge to process the file.
  4. Trigger the overflow: When FontForge parses the SGI file's scanlines, the lack of length validation causes the heap buffer to overflow with attacker-controlled data.
  5. Achieve code execution: By controlling the overflow data, the attacker corrupts heap metadata or function pointers to redirect execution flow, achieving arbitrary code execution in the context of the FontForge process (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected or suspicious SGI image files (.sgi, .rgb, .rgba, .bw) in user download directories or temporary folders; new or modified files in the user's home directory created around the time FontForge was used.
  • Process: Unusual child processes spawned by the FontForge process (e.g., shell interpreters, network utilities like curl, wget, or nc); FontForge crashing unexpectedly or producing core dump files.
  • Network: Unexpected outbound network connections originating from the FontForge process to external IP addresses, particularly shortly after opening an SGI file.
  • Logs: Application crash logs or core dumps referencing FontForge's GUtils or SGI parsing routines; system logs showing abnormal process creation events tied to the FontForge PID.

Mitigation and workarounds

No official patch from the FontForge project has been released; the vendor rejected the vulnerability report in December 2025, stating they would only accept pull requests that include the required fixes. Red Hat has opened a tracking bug (Bug 2426425) but no fixed version has been confirmed as of the latest update. The primary recommended mitigation is to restrict user interaction with FontForge and avoid opening SGI files from untrusted sources. Users should limit FontForge usage to trusted environments and monitor Red Hat and distribution-specific advisories for downstream patches (ZDI Advisory, Red Hat Bugzilla).

Community reactions

The Zero Day Initiative published the advisory as a 0-day on December 29, 2025, after an extended disclosure timeline during which the FontForge vendor rejected the report and declined to engage without a ready-made fix. The disclosure generated discussion on social platforms including Mastodon and Bluesky, with security community accounts such as TheHackerWire amplifying the advisory. The vendor's rejection of the vulnerability report without providing a patch drew attention to the challenges of responsible disclosure when upstream maintainers are unresponsive or set unconventional acceptance criteria (ZDI Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util-bdb
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util-ldap
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util-ldap
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util-sqlite
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management