oss-sec mailing list archives
Re: Null Pointer Dereference in HarfBuzz
From: Jan Engelhardt <ej () inai de>
Date: Mon, 12 Jan 2026 10:42:33 +0100 (CET)
On Monday 2026-01-12 04:09, Jacob Bachmeyer wrote:
In short, this is a crash bug, but not a security issue. This is different from (for example) a parser bug that results in NULL being dereferenced if crafted input is processed. Are we now using CVE IDs as some kind of global bug tracker?
Isn't that how the Linux kernel works these days, as per <https://docs.kernel.org/process/cve.html>: "almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed"
Current thread:
- Null Pointer Dereference in HarfBuzz Alan Coopersmith (Jan 10)
- Re: Null Pointer Dereference in HarfBuzz Jacob Bachmeyer (Jan 11)
- Re: Null Pointer Dereference in HarfBuzz Jan Engelhardt (Jan 12)
- Re: Null Pointer Dereference in HarfBuzz Greg KH (Jan 12)
- Re: Null Pointer Dereference in HarfBuzz Jacob Bachmeyer (Jan 13)
- Re: Null Pointer Dereference in HarfBuzz Jan Engelhardt (Jan 12)
- Re: Null Pointer Dereference in HarfBuzz Vincent Lefevre (Jan 12)
- Re: Null Pointer Dereference in HarfBuzz Jacob Bachmeyer (Jan 12)
- Re: Null Pointer Dereference in HarfBuzz Vincent Lefevre (Jan 13)
- Re: Null Pointer Dereference in HarfBuzz Jacob Bachmeyer (Jan 13)
- Re: Null Pointer Dereference in HarfBuzz Jacob Bachmeyer (Jan 11)
