libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
| Software | From | Fixed in |
|---|---|---|
| libass_project / libass | 0.15.0 | 0.15.1 |
| fedoraproject / fedora | 34 | 34.x |