Stack-based buffer overflow in Ghostscript - CVE-2025-59798
Published: November 17, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the pdf_write_cmap() function in devices/vector/gdevpdtw.c. A remote attacker can trick the victim into opening a specially crafted file to trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
ghostscript (Ubuntu package)
ghostscript-x11-debuginfo
ghostscript-devel
ghostscript-x11
ghostscript-debuginfo
ghostscript-debugsource
ghostscript
ghostscript-help
ghostscript-tools-dvipdf
ghostscript (Debian package)
ghostscript-doc
libgs-devel
libgs
ghostscript-tools-printing
ghostscript-tools-fonts
ghostscript-gtk
How to mitigate CVE-2025-59798
ghostscript-x11-debuginfo - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript-devel - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript-x11 - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript-debuginfo - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript-debugsource - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript-debugsource - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript-help - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript-tools-dvipdf - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript-devel - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript-debuginfo - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript (Debian package) - addressed in versions 10.0.0~dfsg-11+deb12u8, 10.05.1~dfsg-1+deb13u1
ghostscript-doc - update to 10.05.1-3
libgs-devel - update to 10.05.1-3
libgs - update to 10.05.1-3
ghostscript-x11 - update to 10.05.1-3
ghostscript-tools-printing - update to 10.05.1-3
ghostscript-tools-fonts - update to 10.05.1-3
ghostscript-tools-dvipdf - update to 10.05.1-3
ghostscript-gtk - update to 10.05.1-3
ghostscript - update to 10.05.1-3
External References
Related Security Bulletins
- Multiple vulnerabilities in Artifex Ghostscript
- SUSE update for ghostscript
- Anolis OS update for ghostscript
- SUSE update for ghostscript
- Debian update for ghostscript
- Ubuntu update for ghostscript
- Ubuntu update for ghostscript
- openEuler 24.03 LTS update for ghostscript
- openEuler 22.03 LTS SP4 update for ghostscript
- openEuler 20.03 LTS SP4 update for ghostscript
- openEuler 24.03 LTS SP2 update for ghostscript
- openEuler 24.03 LTS SP1 update for ghostscript