VDB
Sign up
MEDIUM

GHSA-c55g-rp4x-fx84

Microsoft DirectX: .spritefont multiply overflow only in 32-bit builds

Quick fix

GHSA-c55g-rp4x-fx84 — directxtk_desktop_win10: upgrade to the fixed version with the command below.

dotnet add package directxtk_desktop_win10 --version 2026.5.8.1

Details

### Impact The spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.

This impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.

> Note this only applies to x86/ARM builds of the library. ARM64 and x64 native is not subject to this issue.

### Patches This bug has been fixed in the May 7, 2026 release. Alternatively, users can update their copy of the reader as per [this commit](https://github.com/microsoft/DirectXTK/commit/ef1bd5d7f492c39dd0cd87493ba8ea38725c9791).

### Workarounds This does not apply if a project's .spritefont files are all 'trusted' data that were included with an application. It's primarily an issue only if developers are using user-provided or network downloaded spritefont files.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/directxtk_desktop_win10
Introduced in: 0Fixed in: 2026.5.8.1
Fixdotnet add package directxtk_desktop_win10 --version 2026.5.8.1
NuGet/directxtk_uwp
Introduced in: 0Fixed in: 2026.5.8.1
Fixdotnet add package directxtk_uwp --version 2026.5.8.1

References