Ubuntu FreeType Update Fixes CVE-2026-95512
Quick Answer
Ubuntu published USN-8881-1 for FreeType on Ubuntu 26.04 (resolute) LTS, Ubuntu 24.04 (noble) LTS, Ubuntu 22.04 (jammy) LTS. Ubuntu does not state a CVSS base score in these notices. Install the fixed source-package versions for the exact release.
Match USN-8881-1 To Ubuntu Releases And Update
What to do now: Inventory affected Ubuntu releases, compare installed source-package versions with the notices, install the supported updates, validate dependent workloads, and retain evidence.
Last verified: 2026-10-06 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | FreeType on Ubuntu 26.04 (resolute) LTS, Ubuntu 24.04 (noble) LTS, Ubuntu 22.04 (jammy) LTS |
|---|---|
| Advisory | USN-8881-1 |
| CVE | CVE-2026-95512 |
| Authoritative release date | 2026-10-06 12:07:59.340614 UTC |
| Authority revision date | 2026-10-06 12:07:59.340614 UTC |
| Affected versions | The Ubuntu releases and source packages enumerated in USN-8881-1: Ubuntu 26.04 (resolute) LTS, Ubuntu 24.04 (noble) LTS, Ubuntu 22.04 (jammy) LTS. |
| Fixed version | jammy: freetype 2.11.1+dfsg-1ubuntu0.4 / noble: freetype 2.13.2+dfsg-1ubuntu0.2 / resolute: freetype 2.14.2+dfsg-1ubuntu0.2 |
| CVSS base score | Not provided by the authority |
| CVSS severity | Not provided by the authority |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
FreeType could be made to crash if it opened a specially crafted file. In general, a standard system update will make all the necessary changes.
What To Validate Now
- Inventory. Locate systems on Ubuntu 26.04 (resolute) LTS, Ubuntu 24.04 (noble) LTS, Ubuntu 22.04 (jammy) LTS; record the installed source package, repository pocket, ESM entitlement where applicable, owner, exposure, and dependencies.
- Establish applicability. Match the Ubuntu codename and source package to USN-8881-1. Do not infer applicability from a binary package name, a generic kernel label, or the number of CVEs alone.
- Remediate. Install the fixed source-package versions listed by Ubuntu through the supported security or ESM channel.
- Validate. Confirm the installed source-package version, test representative FreeType functions and recovery paths, and document exceptions.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Test representative fonts, document rendering, browsers, desktop sessions, print paths, and server-side image or PDF generation after updating. Preserve package-manager output, before-and-after versions, validation results, and rollback evidence.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

