{"id":"GHSA-c55g-rp4x-fx84","aliases":[],"url":"https://o3.security/vulnerability/GHSA-c55g-rp4x-fx84","summary":"Microsoft DirectX: .spritefont multiply overflow only in 32-bit builds","details":"### Impact\nThe spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.\n\nThis impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.\n\n> Note this only applies to x86/ARM builds of the library. ARM64 and x64 native is not subject to this issue.\n\n### Patches\nThis bug has been fixed in the May 7, 2026 release. Alternatively, users can update their copy of the reader as per [this commit](https://github.com/microsoft/DirectXTK/commit/ef1bd5d7f492c39dd0cd87493ba8ea38725c9791).\n\n### Workarounds\nThis does not apply if a project's .spritefont files are all 'trusted' data that were included with an application. It's primarily an issue only if developers are using user-provided or network downloaded spritefont files.","published":"2026-05-18T15:38:15Z","modified":"2026-05-18T15:49:39.538575Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"directxtk_desktop_win10","fixedVersion":"2026.5.8.1"},{"ecosystem":"NuGet","name":"directxtk_uwp","fixedVersion":"2026.5.8.1"}],"fix":{"url":"https://github.com/microsoft/DirectXTK/commit/ef1bd5d7f492c39dd0cd87493ba8ea38725c9791","label":"microsoft/DirectXTK@ef1bd5d"},"references":[{"type":"WEB","url":"https://github.com/microsoft/DirectXTK/security/advisories/GHSA-c55g-rp4x-fx84"},{"type":"WEB","url":"https://github.com/microsoft/DirectXTK/commit/ef1bd5d7f492c39dd0cd87493ba8ea38725c9791"},{"type":"PACKAGE","url":"https://github.com/microsoft/DirectXTK"},{"type":"WEB","url":"https://github.com/microsoft/DirectXTK/releases/tag/may2026"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-18T15:49:39.538575Z"}}