{"id":"GHSA-5r97-79vw-qvm4","aliases":[],"url":"https://o3.security/vulnerability/GHSA-5r97-79vw-qvm4","summary":"Microsoft DirectX12: .spritefont multiply overflow only in 32-bit builds","details":"### Impact\nThe spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.\n\nThis impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.\n\n> Note this only applies to x86/ARM builds of the library. ARM64 and x64 native is not subject to this issue.\n\n### Patches\nThis bug has been fixed in the May 7, 2026 release. Alternatively, you can just update your copy of the reader as per [this commit](https://github.com/microsoft/DirectXTK12/commit/c037a024a7ed3b2162fa2bbbe209b84ba2904494).\n\n### Workarounds\nThis does not apply if a project's .spritefont files are all 'trusted' data that were included with an application. It's primarily an issue only if developers are using user-provided or network downloaded spritefont files.","published":"2026-05-18T15:38:59Z","modified":"2026-05-18T15:49:42.342845Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"directxtk12_desktop_win10","fixedVersion":"2026.5.8.1"},{"ecosystem":"NuGet","name":"directxtk12_uwp","fixedVersion":"2026.5.8.1"}],"fix":{"url":"https://github.com/microsoft/DirectXTK12/commit/c037a024a7ed3b2162fa2bbbe209b84ba2904494","label":"microsoft/DirectXTK12@c037a02"},"references":[{"type":"WEB","url":"https://github.com/microsoft/DirectXTK12/security/advisories/GHSA-5r97-79vw-qvm4"},{"type":"WEB","url":"https://github.com/microsoft/DirectXTK12/commit/c037a024a7ed3b2162fa2bbbe209b84ba2904494"},{"type":"PACKAGE","url":"https://github.com/microsoft/DirectXTK12"},{"type":"WEB","url":"https://github.com/microsoft/DirectXTK12/releases/tag/may2026"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-18T15:49:42.342845Z"}}