Amazon Linux 2023 Security Advisory: ALAS-2025-848
Advisory Release Date: 2025-02-12 22:57 Pacific
Advisory Updated Date: 2025-02-21 13:45 Pacific
HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function. (CVE-2024-56732)
Affected Packages:
harfbuzz
Issue Correction:
Run dnf update harfbuzz --releasever 2023.6.20250218 to update your system.
aarch64:
harfbuzz-debuginfo-7.0.0-2.amzn2023.0.2.aarch64
harfbuzz-icu-7.0.0-2.amzn2023.0.2.aarch64
harfbuzz-icu-debuginfo-7.0.0-2.amzn2023.0.2.aarch64
harfbuzz-devel-debuginfo-7.0.0-2.amzn2023.0.2.aarch64
harfbuzz-7.0.0-2.amzn2023.0.2.aarch64
harfbuzz-devel-7.0.0-2.amzn2023.0.2.aarch64
harfbuzz-debugsource-7.0.0-2.amzn2023.0.2.aarch64
src:
harfbuzz-7.0.0-2.amzn2023.0.2.src
x86_64:
harfbuzz-icu-7.0.0-2.amzn2023.0.2.x86_64
harfbuzz-devel-debuginfo-7.0.0-2.amzn2023.0.2.x86_64
harfbuzz-debuginfo-7.0.0-2.amzn2023.0.2.x86_64
harfbuzz-icu-debuginfo-7.0.0-2.amzn2023.0.2.x86_64
harfbuzz-7.0.0-2.amzn2023.0.2.x86_64
harfbuzz-devel-7.0.0-2.amzn2023.0.2.x86_64
harfbuzz-debugsource-7.0.0-2.amzn2023.0.2.x86_64