NULL pointer dereference in GhostPDL - CVE-2025-7462

 

NULL pointer dereference in GhostPDL - CVE-2025-7462

Published: December 1, 2025


Vulnerability identifier: #VU118854
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-7462
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error within the pdf_ferror() function in devices/vector/gdevpdf.c. A remote attacker can pass specially crafted file to the application and perform a denial of service (DoS) attack.


Affected software

GhostPDL
Debian Linux
openEuler
Ubuntu
Anolis OS
ghostscript-tools-dvipdf
ghostscript-devel
ghostscript-debugsource
ghostscript-debuginfo
ghostscript
ghostscript-help
ghostscript (Ubuntu package)
ghostscript (Debian package)
ghostscript-doc
libgs
ghostscript-tools-printing
ghostscript-gtk
ghostscript-x11
ghostscript-tools-fonts
libgs-devel

How to mitigate CVE-2025-7462

Install update from vendor's website.

ghostscript-tools-dvipdf - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript-devel - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript-debugsource - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript-debuginfo - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript-help - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript (Ubuntu package) - addressed in versions 9.55.0~dfsg1-0ubuntu5.13, 10.02.1~dfsg1-0ubuntu7.8, 10.05.0dfsg1-0ubuntu1.2
ghostscript (Debian package) - addressed in versions 10.0.0~dfsg-11+deb12u8, 10.05.1~dfsg-1+deb13u1
ghostscript-doc - update to 10.05.1-5
libgs - update to 10.05.1-5
ghostscript-tools-printing - update to 10.05.1-5
ghostscript-gtk - update to 10.05.1-5
ghostscript-tools-dvipdf - update to 10.05.1-5
ghostscript-x11 - update to 10.05.1-5
ghostscript-tools-fonts - update to 10.05.1-5
ghostscript - update to 10.05.1-5
libgs-devel - update to 10.05.1-5

External References

Related Security Bulletins