RHEL fontforge Remote Code Execution Vulnerability - CVSS 8.8
Summary
CERT-Bund issued a security advisory regarding a critical vulnerability (CVSS 8.8) in Red Hat Enterprise Linux's fontforge component affecting versions prior to RHEL 10, RHEL 9, and RHEL Extended Update Support 9.6. The vulnerability allows remote, unauthenticated attackers to execute arbitrary code on affected systems. Organizations running affected RHEL distributions should apply available mitigations or patches immediately.
What changed
CERT-Bund published a high-severity security advisory alerting organizations to a remote code execution vulnerability in the fontforge component of Red Hat Enterprise Linux. The vulnerability carries a CVSS Base Score of 8.8 and enables remote, anonymous attackers to execute arbitrary code without authentication. Affected versions include RHEL versions prior to 10, 9, and Extended Update Support 9.6.
Organizations operating Red Hat Enterprise Linux systems must prioritize remediation given the critical severity and remote exploitation capability. System administrators should apply patches immediately or implement vendor-specified workarounds to prevent potential compromise through this attack vector.
What to do next
- Apply available patches for Red Hat Enterprise Linux to the latest secure versions
- Implement mitigation measures as specified by Red Hat if immediate patching is not feasible
- Audit systems for indicators of compromise if fontforge is deployed
Archived snapshot
Apr 8, 2026GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.
[WID-SEC-2026-0967] Red Hat Enterprise Linux (fontforge): Schwachstelle ermöglicht Codeausführung CVSS Base Score 8.8 (hoch) CVSS Temporal Score 7.7 (hoch) Remoteangriff ja Datum 06.04.2026 Stand 07.04.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Linux
- UNIX
Produktbeschreibung
Red Hat Enterprise Linux (RHEL) ist eine populäre Linux-Distribution.
Produkte
06.04.2026
- Red Hat Enterprise Linux <10
Red Hat Enterprise Linux <9
Red Hat Enterprise Linux Extended Update Support <9.6
Angriff
Angriff
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (fontforge) ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Get daily alerts for CERT-Bund Security Advisories
Daily digest delivered to your inbox.
Free. Unsubscribe anytime.
Source
About this page
Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission
Source document text, dates, docket IDs, and authority are extracted directly from CERT-Bund.
The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.
Classification
Who this affects
Taxonomy
Browse Categories
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.
Subscribed!
Optional. Filters your digest to exactly the updates that matter to you.