
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15277 is a heap-based buffer overflow vulnerability in FontForge's SGI file parser that allows remote attackers to execute arbitrary code on affected installations. The flaw exists within the parsing of scanlines in SGI image files, where user-supplied data length is not properly validated before being copied to a heap-based buffer. It affects FontForge version 20251009 and was publicly disclosed on December 29, 2025, as a zero-day advisory after the vendor rejected the vulnerability report. The CVSS v3.0 base score is 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and resides in the GUtils component responsible for parsing SGI image file scanlines. The root cause is the absence of proper length validation of user-supplied data before it is copied into a heap-allocated buffer, enabling a classic heap overflow condition. Exploitation requires user interaction — specifically, the target must open a malicious SGI file or visit a malicious page that triggers the file parsing. The vulnerability was discovered by researcher volticks (@movx64) and tracked internally by ZDI as ZDI-CAN-27920 (ZDI Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the FontForge process, potentially leading to full compromise of confidentiality, integrity, and availability on the affected system. Since FontForge typically runs with user-level privileges, an attacker could access files and data accessible to that user, install malware, or pivot to further attacks within the environment. The attack vector is local (the malicious file must be opened), but delivery can be achieved remotely by tricking a user into opening a crafted SGI file (ZDI Advisory, Red Hat Bugzilla).
A proof-of-concept exploit is publicly available via the Zero Day Initiative advisory, published on December 29, 2025, as a 0-day after the vendor rejected the vulnerability report. There is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.042%, indicating a low but non-zero probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (ZDI Advisory).
.sgi, .rgb, .rgba, .bw) in user download directories or temporary folders; new or modified files in the user's home directory created around the time FontForge was used.curl, wget, or nc); FontForge crashing unexpectedly or producing core dump files.No official patch from the FontForge project has been released; the vendor rejected the vulnerability report in December 2025, stating they would only accept pull requests that include the required fixes. Red Hat has opened a tracking bug (Bug 2426425) but no fixed version has been confirmed as of the latest update. The primary recommended mitigation is to restrict user interaction with FontForge and avoid opening SGI files from untrusted sources. Users should limit FontForge usage to trusted environments and monitor Red Hat and distribution-specific advisories for downstream patches (ZDI Advisory, Red Hat Bugzilla).
The Zero Day Initiative published the advisory as a 0-day on December 29, 2025, after an extended disclosure timeline during which the FontForge vendor rejected the report and declined to engage without a ready-made fix. The disclosure generated discussion on social platforms including Mastodon and Bluesky, with security community accounts such as TheHackerWire amplifying the advisory. The vendor's rejection of the vulnerability report without providing a patch drew attention to the challenges of responsible disclosure when upstream maintainers are unresponsive or set unconventional acceptance criteria (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."