ALAS-2025-848


Amazon Linux 2023 Security Advisory: ALAS-2025-848
Advisory Release Date: 2025-02-12 22:57 Pacific
Advisory Updated Date: 2025-02-21 13:45 Pacific
Severity: Medium

Issue Overview:

HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function. (CVE-2024-56732)


Affected Packages:

harfbuzz


Issue Correction:
Run dnf update harfbuzz --releasever 2023.6.20250218 to update your system.

New Packages:
aarch64:
    harfbuzz-debuginfo-7.0.0-2.amzn2023.0.2.aarch64
    harfbuzz-icu-7.0.0-2.amzn2023.0.2.aarch64
    harfbuzz-icu-debuginfo-7.0.0-2.amzn2023.0.2.aarch64
    harfbuzz-devel-debuginfo-7.0.0-2.amzn2023.0.2.aarch64
    harfbuzz-7.0.0-2.amzn2023.0.2.aarch64
    harfbuzz-devel-7.0.0-2.amzn2023.0.2.aarch64
    harfbuzz-debugsource-7.0.0-2.amzn2023.0.2.aarch64

src:
    harfbuzz-7.0.0-2.amzn2023.0.2.src

x86_64:
    harfbuzz-icu-7.0.0-2.amzn2023.0.2.x86_64
    harfbuzz-devel-debuginfo-7.0.0-2.amzn2023.0.2.x86_64
    harfbuzz-debuginfo-7.0.0-2.amzn2023.0.2.x86_64
    harfbuzz-icu-debuginfo-7.0.0-2.amzn2023.0.2.x86_64
    harfbuzz-7.0.0-2.amzn2023.0.2.x86_64
    harfbuzz-devel-7.0.0-2.amzn2023.0.2.x86_64
    harfbuzz-debugsource-7.0.0-2.amzn2023.0.2.x86_64