hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
| Software | From | Fixed in |
|---|---|---|
| harfbuzz_project / harfbuzz | - | 6.0.0.x |
| fedoraproject / fedora | 36 | 36.x |