high · CVSS v3 6.3 · CVSS v4 5.3
CVE-2026-103226
A stack-based buffer overflow exists in Artifex Ghostscript’s Pdfwrite component (type1_callsubr) that can be triggered remotely via crafted
Overview
A stack-based buffer overflow exists in Artifex Ghostscript’s Pdfwrite component (type1_callsubr) that can be triggered remotely via crafted PDF files. The flaw is present in versions up to 10.09.0 and has a publicly available exploit. Updating Ghostscript mitigates the risk.
Description
A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: "I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.
Impact
The vulnerability can lead to arbitrary code execution, compromising confidentiality, integrity, and availability of systems that process PDFs with Ghostscript. Defenders managing document conversion, printing services, or web servers that rely on Ghostscript are directly impacted.
Remediation
Apply the official patch or upgrade to Ghostscript 10.09.1 or later. If an upgrade is not immediately possible, disable the Pdfwrite component or restrict PDF input to trusted sources. Verify the update by checking the version string and test with known safe PDFs.
Risk context
Severity is high (CVSS v3 6.3) and the exploit is publicly available, making the issue urgent for systems that expose Ghostscript to untrusted input.
Affected products
- Artifex Ghostscript
- Ghostscript 10.09.0
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 6.3
- CVSS v4
- 5.3
- EPSS
- —