Executive brief
PDFio is a C library used to read and write PDF files. A flaw in its dictionary string-formatting function stores a pointer to temporary stack memory instead of creating a copy, potentially allowing concurrent requests in multi-threaded environments to corrupt each other's document content. This could lead to silent data corruption where one user's data overwrites another user's PDF dictionary values.
Technical details
The vulnerability is a dangling pointer bug in the pdfioDictSetStringf() function, which formats and stores strings in a PDF document dictionary. Instead of copying the formatted string value, the function stores a pointer to a stack-local buffer that is freed when the function returns. In multi-threaded or connection-pooled server environments, concurrent requests can cause stack memory to be reused and overwritten, resulting in cross-tenant or cross-request dictionary corruption. The attack requires no authentication and occurs silently without triggering errors. The fix, available in PDFio 1.6.5, ensures the function properly copies the formatted string rather than storing a dangling pointer.
Affected products
- michaelrsweet PDFio before 1.6.5
Timeline
- 2026-08-21: disclosed
- 2026-08-20: patched: PDFio 1.6.5 released