News

USN-8881-1: DoS flaw in FreeType, update libfreetype6 on Ubuntu

A malicious font file can cause FreeType to consume excessive CPU and memory. Ubuntu has released patches for 22.04, 24.04 and 26.04 LTS.

UptimeMag editorial team · 6 October 2026 · 1 min read

USN-8881-1: falla DoS in FreeType, aggiornare libfreetype6 su Ubuntu

Ubuntu has published security advisory USN-8881-1, which fixes a vulnerability in FreeType, the font-rendering library used by a wide range of services on Linux servers: PDF generation, image rendering, control panels and web applications that produce graphical output. For anyone managing Ubuntu servers, this is an update to apply during the normal patching cycle.

The issue

According to the official advisory published on 6 October 2026, a flaw was discovered in FreeType's CID font loader. An attacker could exploit the flaw by getting the library to open a specially crafted file, causing excessive memory and CPU consumption and leading to a denial of service. The vulnerability is tracked as CVE-2026-95512.

Fixed versions

Ubuntu release Codename Package and version
26.04 LTS resolute libfreetype6 2.14.2+dfsg-1ubuntu0.2
24.04 LTS noble libfreetype6 2.13.2+dfsg-1ubuntu0.2
22.04 LTS jammy libfreetype6 2.11.1+dfsg-1ubuntu0.4

How to update

As indicated by Ubuntu, a standard system upgrade will typically apply the necessary changes automatically:

sudo apt update && sudo apt upgrade

No reboot is required, since this is a userspace library rather than the kernel. That said, after updating it's good practice to restart any services that depend on libfreetype6 (for example, those generating PDFs or images) so that the patched version is loaded into memory.

Ubuntu also notes that Ubuntu Pro offers ten years of security coverage for over 25,000 packages in the Main and Universe repositories, free of charge for up to five machines.

Source: official advisory USN-8881-1 published at ubuntu.com/security/notices, 6 October 2026.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.