Hello,
I have identified a reproducible memory-safety issue in ttf2mesh.
The issue is reachable through the public font-loading API / TTF parsing path on a clean checkout with AddressSanitizer enabled. I have prepared a small report package containing:
affected commit information
standalone reproducers
minimized malformed input
ASan/UBSan run logs
source-level root cause notes
clean-checkout reproduction steps
suggested fix direction
I would prefer not to disclose the malformed input, reproducer details, or sanitizer output publicly before the maintainer has had a chance to review them.
Is there a preferred private security contact, email address, or disclosure route for this project?
Best regards,
Yukimura
Hello,
I have identified a reproducible memory-safety issue in ttf2mesh.
The issue is reachable through the public font-loading API / TTF parsing path on a clean checkout with AddressSanitizer enabled. I have prepared a small report package containing:
affected commit information
standalone reproducers
minimized malformed input
ASan/UBSan run logs
source-level root cause notes
clean-checkout reproduction steps
suggested fix direction
I would prefer not to disclose the malformed input, reproducer details, or sanitizer output publicly before the maintainer has had a chance to review them.
Is there a preferred private security contact, email address, or disclosure route for this project?
Best regards,
Yukimura