hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
2023-02-04T20:15:08.027
2025-03-25T21:15:41.240
Modified
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | harfbuzz_project | harfbuzz | ≤ 6.0.0 | Yes |
| Operating System | fedoraproject | fedora | 36 | Yes |