Executive brief
MuPDF is a lightweight software library used for viewing and converting PDF and e-book files. A security flaw allows a specially crafted PDF file to cause the application to crash or potentially allow an attacker to take control of the system. This risk is highest for services that automatically process or display documents from untrusted sources.
Technical details
An integer overflow vulnerability exists in 'pdf-image.c' within the 'pdf_load_image_imp' function of MuPDF. The root cause is insufficient validation of image parameters (width, height, and bits per component) against integer limits during stride calculations. When a maliciously crafted PDF provides extremely large values, the resulting overflow leads to an undersized buffer allocation. Subsequent processing in 'fz_unpack_stream' then performs a heap out-of-bounds write. This can be exploited for arbitrary code execution or denial of service (crash) when a user or automated system renders a malformed document. A patch has been identified in the project's source repository using 64-bit math to prevent the overflow.
Affected products
- Artifex Software MuPDF <= 1.27.0
Timeline
- 2026-01-05: patched: Fix committed to upstream repository
- 2026-03-31: disclosed: Initial CVE publication
- 2026-04-02: advisory: CERT/CC vulnerability note published
- 2026-04-21: patched: Debian LTS security update released
References
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=a26f0142e7d390d4a82c6e5ae0e312e07cc4ec85
- https://github.com/ArtifexSoftware/mupdf
- https://github.com/ArtifexSoftware/mupdf/commit/a26f0142e7d390d4a82c6e5ae0e312e07cc4ec85
- https://lists.debian.org/debian-lts-announce/2026/04/msg00020.html
- https://www.kb.cert.org/vuls/id/951662