Back

MEDIUM

Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS

Published Jan 10, 2026

Description

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.

Affected products

Remediation

Red Hat statement

This MODERATE severity null pointer dereference in the HarfBuzz library may cause a denial of service (segmentation fault) when memory allocation fails in hb_malloc. The issue affects Red Hat products that include and link against HarfBuzz, such as OpenJDK builds with the java.desktop module and certain RHEL components like Firefox and Thunderbird. The java-17-openjdk-headless and java-21-openjdk-headless packages do not include java.desktop and do not link against HarfBuzz; therefore, headless-only environments are not affected.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jan 10, 2026
Updated Jan 12, 2026
Reserved Jan 8, 2026
CISA Vulnrichment
Updated Jan 12, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 10, 2026
ENISA EUVD
Assigner GitHub_M
Published Jan 10, 2026
Updated Jan 12, 2026
Exploited since n/a
EUVD-2026-1871