Debian Package Tracker
Register | Log in
Subscribe

freetype

Choose email to subscribe with

general
  • source: freetype (main)
  • version: 2.14.3+dfsg-3
  • maintainer: Hugh McMaster (DMD)
  • uploaders: Keith Packard [DMD] – Anthony Fok [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.10.4+dfsg-1+deb11u1
  • o-o-sec: 2.10.4+dfsg-1+deb11u2
  • oldstable: 2.12.1+dfsg-5+deb12u4
  • old-sec: 2.12.1+dfsg-5+deb12u4
  • stable: 2.13.3+dfsg-1+deb13u1
  • stable-sec: 2.13.3+dfsg-1+deb13u1
  • testing: 2.14.3+dfsg-2
  • unstable: 2.14.3+dfsg-3
versioned links
  • 2.10.4+dfsg-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.10.4+dfsg-1+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.12.1+dfsg-5+deb12u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.13.3+dfsg-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.14.3+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.14.3+dfsg-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • freetype2-demos
  • freetype2-doc
  • libfreetype-dev
  • libfreetype6 (2 bugs: 0, 2, 0, 0)
  • libfreetype6-udeb
action needed
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-95512: A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.
Created: 2026-10-02 Last update: 2026-10-05 18:30
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-95512: (needs triaging) A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-10-02 Last update: 2026-10-05 18:30
testing migrations
  • excuses:
    • Migration status for freetype (2.14.3+dfsg-2 to 2.14.3+dfsg-3): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for cataclysm-dda/0.I-1: arm64: Pass ♻
    • ∙ ∙ Autopkgtest for ffmpeg/7:9.0.2-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Regression ♻ (reference ♻), s390x: Pass
    • ∙ ∙ Autopkgtest for freetype/2.14.3+dfsg-3: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻, armhf: No tests, superficial or marked flaky ♻, i386: No tests, superficial or marked flaky ♻, ppc64el: No tests, superficial or marked flaky ♻, riscv64: No tests, superficial or marked flaky ♻, s390x: No tests, superficial or marked flaky ♻
    • ∙ ∙ Autopkgtest for libreoffice/4:26.8.0.3-2: amd64: Pass, arm64: Test triggered (failure will be ignored), armhf: Test triggered (failure will be ignored), i386: Test triggered (failure will be ignored), ppc64el: Pass, riscv64: Pass, s390x: Pass
    • ∙ ∙ Autopkgtest for openjdk-21/21.0.12.1+1-1: amd64: Pass, arm64: Test triggered (failure will be ignored), armhf: Pass, i386: Test triggered (failure will be ignored), ppc64el: Test triggered (failure will be ignored), riscv64: Test triggered (failure will be ignored), s390x: Pass
    • ∙ ∙ Autopkgtest for openjdk-25/25.0.5~7ea-1: amd64: Pass, arm64: Test triggered (failure will be ignored), armhf: Pass, i386: Pass, ppc64el: Test triggered (failure will be ignored), riscv64: Test triggered (failure will be ignored), s390x: Pass
    • ∙ ∙ Autopkgtest for openjdk-26/26.0.2.1+1-1: amd64: Pass, arm64: Test triggered (failure will be ignored), armhf: Pass, i386: Pass, ppc64el: Test triggered (failure will be ignored), riscv64: Test triggered (failure will be ignored), s390x: Pass
    • ∙ ∙ Autopkgtest for openjdk-27/27~34ea-1: amd64: Pass, arm64: Test triggered (failure will be ignored), armhf: Pass, i386: Pass, ppc64el: Test triggered (failure will be ignored), riscv64: Test triggered (failure will be ignored), s390x: Pass
    • ∙ ∙ Autopkgtest for openjdk-28/28~13ea-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Test triggered (failure will be ignored), riscv64: Test triggered (failure will be ignored), s390x: Test triggered (failure will be ignored)
    • ∙ ∙ Autopkgtest for thunderbird/1:153.4.0esr-1: amd64: Pass, arm64: Test triggered (failure will be ignored), i386: Pass, ppc64el: No tests, superficial or marked flaky ♻, riscv64: Test triggered (failure will be ignored), s390x: No tests, superficial or marked flaky ♻
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/f/freetype.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ 5 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2026-10-05] Accepted freetype 2.14.3+dfsg-3 (source) into unstable (Hugh McMaster)
  • [2026-07-31] freetype 2.14.3+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-07-24] Accepted freetype 2.14.3+dfsg-2 (source) into unstable (Hugh McMaster)
  • [2026-04-08] freetype 2.14.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-03] Accepted freetype 2.14.3+dfsg-1 (source) into unstable (Hugh McMaster)
  • [2026-03-19] Accepted freetype 2.13.3+dfsg-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2026-03-18] Accepted freetype 2.13.3+dfsg-1+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2026-03-14] freetype 2.14.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-07] Accepted freetype 2.14.2+dfsg-1 (source) into unstable (Hugh McMaster)
  • [2026-01-04] freetype 2.14.1+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-01-04] freetype 2.14.1+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2025-12-29] Accepted freetype 2.14.1+dfsg-2 (source) into unstable (Hugh McMaster)
  • [2025-12-26] Accepted freetype 2.14.1+dfsg-1 (source) into unstable (Hugh McMaster)
  • [2025-03-31] Accepted freetype 2.10.4+dfsg-1+deb11u2 (source) into oldstable-security (Adrian Bunk)
  • [2025-03-19] Accepted freetype 2.12.1+dfsg-5+deb12u4 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-03-17] Accepted freetype 2.12.1+dfsg-5+deb12u4 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2024-09-10] freetype 2.13.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-05] Accepted freetype 2.13.3+dfsg-1 (source) into unstable (Hugh McMaster)
  • [2024-03-24] Accepted freetype 2.12.1+dfsg-5+deb12u3 (source) into proposed-updates (Debian FTP Masters) (signed by: Hugh McMaster)
  • [2023-09-29] Accepted freetype 2.12.1+dfsg-5+deb12u2 (source amd64 all) into proposed-updates (Debian FTP Masters) (signed by: Hugh McMaster)
  • [2023-09-25] Accepted freetype 2.12.1+dfsg-5+deb12u1 (source amd64 all) into proposed-updates (Debian FTP Masters) (signed by: Hugh McMaster)
  • [2023-09-02] freetype 2.13.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-28] Accepted freetype 2.13.2+dfsg-1 (source) into unstable (Hugh McMaster)
  • [2023-08-22] freetype 2.13.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-17] Accepted freetype 2.13.1+dfsg-1 (source) into unstable (Hugh McMaster)
  • [2023-07-18] freetype 2.13.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-13] Accepted freetype 2.13.0+dfsg-1 (source) into unstable (Hugh McMaster)
  • [2023-05-02] freetype 2.12.1+dfsg-5 MIGRATED to testing (Debian testing watch)
  • [2023-04-27] Accepted freetype 2.12.1+dfsg-5 (source) into unstable (Hugh McMaster)
  • [2023-01-17] freetype 2.12.1+dfsg-4 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.14.3+dfsg-2ubuntu1
  • 6 bugs (1 patch)

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing