https://bugzilla.redhat.com/show_bug.cgi?id=2451645
Bug ID: 2451645 Summary: CVE-2026-34085 fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash [fedora-all] Product: Fedora Version: rawhide Status: NEW Whiteboard: {"flaws": ["65df9a0b-8d8a-40c1-a4e1-f6ae7b5cc3e9"]} Component: fontconfig Keywords: Security, SecurityTracking Severity: medium Priority: medium Assignee: tagoh@redhat.com Reporter: trathi@redhat.com QA Contact: extras-qa@fedoraproject.org CC: ajax@redhat.com, fonts-bugs@lists.fedoraproject.org, i18n-bugs@lists.fedoraproject.org, mclasen@redhat.com, rstrode@redhat.com, tagoh@redhat.com Blocks: 2451414 (CVE-2026-34085) Target Milestone: --- Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=2451414 [Bug 2451414] CVE-2026-34085 fontconfig: Fontconfig: Security flaw allows arbitrary code execution or system crash
https://bugzilla.redhat.com/show_bug.cgi?id=2451645
Akira TAGOH tagoh@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Resolution|--- |CURRENTRELEASE Status|NEW |CLOSED Last Closed| |2026-04-07 09:30:50
--- Comment #1 from Akira TAGOH tagoh@redhat.com --- The fixed patch has already been backported in 2.17.0-2 (https://src.fedoraproject.org/rpms/fontconfig/c/8bca22ae6843289d280f9d03098b...) and we currently have:
2.16.0-2.fc42 in f42 (not targeted) 2.17.0-3.fc43 in f43 (fixed) 2.17.0-4.fc44 in f44 (fixed) 2.17.0.4.fc44 in rawhide (fixed)
fonts-bugs@lists.fedoraproject.org