Vulnerability Description
Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/Landw-hub/CVE-2025-50422
- https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/621
- https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591
- https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591#note_3045081
FAQ
What is CVE-2025-50422?
CVE-2025-50422 is a vulnerability with a CVSS score of 2.9 (LOW). Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.
How severe is CVE-2025-50422?
CVE-2025-50422 has been rated LOW with a CVSS base score of 2.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-50422?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.