GHSA-5r97-79vw-qvm4
Microsoft DirectX12: .spritefont multiply overflow only in 32-bit builds
Quick fix
GHSA-5r97-79vw-qvm4 — directxtk12_desktop_win10: upgrade to the fixed version with the command below.
dotnet add package directxtk12_desktop_win10 --version 2026.5.8.1Details
### Impact The spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.
This impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.
> Note this only applies to x86/ARM builds of the library. ARM64 and x64 native is not subject to this issue.
### Patches This bug has been fixed in the May 7, 2026 release. Alternatively, you can just update your copy of the reader as per [this commit](https://github.com/microsoft/DirectXTK12/commit/c037a024a7ed3b2162fa2bbbe209b84ba2904494).
### Workarounds This does not apply if a project's .spritefont files are all 'trusted' data that were included with an application. It's primarily an issue only if developers are using user-provided or network downloaded spritefont files.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2026.5.8.1dotnet add package directxtk12_desktop_win10 --version 2026.5.8.10Fixed in: 2026.5.8.1dotnet add package directxtk12_uwp --version 2026.5.8.1