mediumVulnerability

GHSA-5r97-79vw-qvm4

### Impact The spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE. This impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files. > Note this only applies to x86/ARM builds of the library. ARM64 and x64 native is not subject to this issue. ### Patches This bug has been fixed in the May 7, 2026 release. Alternatively, you can just update your copy of the reader as per [this commit](https://github.com/microsoft/DirectXTK12/commit/c037a024a7ed3b2162fa2bbbe209b84ba2904494). ### Workarounds This does not apply if a project's .spritefont files are all 'trusted' data that were included with an application. It's primarily an issue only if developers are using user-provided or network downloaded spritefont files.

Properties

ghsa_id
GHSA-5r97-79vw-qvm4
severity
medium
summary
Microsoft DirectX12: .spritefont multiply overflow only in 32-bit builds
cve_id
GHSA-5r97-79vw-qvm4
is_ghsa_only
true
ghsa_published
2026-05-18T15:38:59Z
source_url
https://github.com/advisories/GHSA-5r97-79vw-qvm4
ghsa_updated
2026-05-18T15:39:00Z

Related Entities (6)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (2)

[Software]nuget/directxtk12_desktop_win10
[Software]nuget/directxtk12_uwp

AFFECTS (2)

[Software]nuget/directxtk12_desktop_win10
[Software]nuget/directxtk12_uwp

HAS_WEAKNESS (1)

[Weakness]Integer Overflow or Wraparound

Explore deeper with Ninja Signal's threat intelligence graph