CVE-2026-101258

NameCVE-2026-101258
DescriptionA flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ghostscript (PTS)bookworm, bookworm (security)10.0.0~dfsg-11+deb12u8vulnerable
trixie10.05.1~dfsg-1+deb13u1vulnerable
trixie (security)10.05.1~dfsg-1+deb13u2vulnerable
forky, sid10.08.0~dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ghostscriptsource(unstable)10.08.0~dfsg-1

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2542396
https://github.com/v12-security/pocs/tree/main/ghostscript
https://bugs.ghostscript.com/show_bug.cgi?id=709461
Fixed by: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=9d8b70ad1301c9993155dcf53401df3eac14fa4f (ghostpdl-10.08.0)
https://bugs.ghostscript.com/show_bug.cgi?id=709462
Fixed by: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=3d8a1db60895493d73aeef89903d34da9837bc0a (ghostpdl-10.08.0)

Search for package or bug name: Reporting problems