CVE-2025-15280
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-15280 is a use-after-free (UAF) remote code execution vulnerability in FontForge's SFD (Spline Font Database) file parser. It affects FontForge version 2025-11-17 and allows remote attackers to execute arbitrary code when a user opens a malicious SFD file or visits a malicious page. The vulnerability was reported to the vendor on December 12, 2025, and publicly disclosed as a 0-day advisory on December 29, 2025, after the vendor rejected the report. It carries a CVSS v3.0 base score of 8.8 (High) (ZDI Advisory, Red Hat Bugzilla).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and exists within FontForge's parsing logic for SFD files. The flaw stems from a failure to validate whether an object still exists before performing operations on it during file parsing, leading to memory corruption when a freed object is subsequently accessed. An attacker exploits this by crafting a malicious SFD file that triggers the use-after-free condition when processed by FontForge. The attack vector is network-based (e.g., delivering the file via a malicious web page or email), but requires user interaction — specifically, the target must open the malicious file (ZDI Advisory).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code in the context of the current user running FontForge, granting full access to that user's privileges, files, and system resources. The confidentiality, integrity, and availability impacts are all rated High, meaning an attacker could read sensitive data, modify files, or disrupt system operation. Since FontForge is commonly used by font designers and typographers, exploitation could target creative professionals or supply chain workflows involving font assets (ZDI Advisory, Red Hat Bugzilla).

Exploitation steps

  1. Craft a malicious SFD file: Create a specially crafted Spline Font Database (.sfd) file that triggers a use-after-free condition during FontForge's parsing routine by manipulating object references so that a freed memory object is accessed.
  2. Deliver the payload: Host the malicious SFD file on an attacker-controlled web page or distribute it via email, file-sharing platforms, or other social engineering channels targeting FontForge users (e.g., font designers).
  3. Induce user interaction: Lure the target into opening the malicious SFD file in FontForge, for example by disguising it as a legitimate font project file or embedding a download link in a phishing message.
  4. Trigger the UAF condition: When FontForge parses the malicious SFD file, the lack of object existence validation causes the application to operate on freed memory, resulting in memory corruption.
  5. Achieve code execution: The memory corruption is leveraged to redirect program execution to attacker-controlled code, executing arbitrary commands in the context of the current user (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected or unfamiliar .sfd files in user download directories, temporary folders, or font project directories; new or modified executables/scripts in user home directories following FontForge usage.
  • Process: Unusual child processes spawned by the FontForge process (e.g., bash, sh, cmd.exe, curl, wget, python) that are not typical of normal font editing workflows; FontForge crashing unexpectedly or exhibiting abnormal behavior when opening specific files.
  • Network: Outbound network connections from the FontForge process to unknown or suspicious IP addresses or domains, particularly following the opening of an SFD file; DNS queries to unfamiliar domains initiated by FontForge.
  • Logs: Application crash logs or core dumps associated with FontForge's SFD parsing routines; system logs showing unexpected privilege escalation or new user account creation following FontForge execution.

Mitigation and workarounds

The FontForge vendor rejected the vulnerability report and has not released an official patch; the vendor stated that only pull requests containing required fixes will be considered. Red Hat is tracking the issue via Bugzilla (Bug 2426430), but no fixed version is currently available. The primary recommended mitigation is to restrict user interaction with FontForge and avoid opening SFD files from untrusted or unknown sources. Additional measures include sandboxing FontForge using tools like Firejail or AppArmor, implementing application whitelisting, and monitoring FontForge process behavior for anomalies (ZDI Advisory, Red Hat Bugzilla).

Community reactions

The Zero Day Initiative published the advisory as a 0-day on December 29, 2025, after the FontForge vendor rejected the vulnerability report and declined to engage with the disclosure process, requiring instead that reporters submit pull requests with fixes — an unusual stance that drew attention in the security community. The Hacker Wire covered the vulnerability and shared it on Mastodon and Infosec.Exchange, contributing to broader awareness. Red Hat's security team independently tracked the issue via Bugzilla, signaling concern for downstream Linux distributions that package FontForge (ZDI Advisory, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45568CRITICAL9.9
  • Python logoPython
  • zrok
NoYesJul 16, 2026
CVE-2026-45576HIGH8.3
  • NixOS logoNixOS
  • zrok
NoYesJul 16, 2026
CVE-2026-36590HIGH7.5
  • NixOS logoNixOS
  • nanomq
NoNoJul 15, 2026
CVE-2026-59259MEDIUM6
  • NixOS logoNixOS
  • n8n
NoYesJul 15, 2026
CVE-2026-26032MEDIUM5.4
  • NixOS logoNixOS
  • ivy
NoYesJul 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management