FlawAtlas
Search the atlas
CVE-2023-25193 High

CVE-2023-25193

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

Exploit probability 1.8%
Published May 6, 2026
Required by Not available
Last source change May 8, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

160 explicit affected versions

Bitnami java-min
Bitnami jre
Bitnami java

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2023-25193

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

View original source
Open Source Vulnerabilities BIT-java-2023-25193

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

View original source
Open Source Vulnerabilities BIT-java-min-2023-25193

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

View original source
Open Source Vulnerabilities BIT-jre-2023-25193

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

View original source

05 / REFERENCES

Further evidence