NULL pointer dereference in GhostPDL - CVE-2025-7462
Published: December 1, 2025
Vulnerability identifier: #VU118854
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-7462
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the pdf_ferror() function in devices/vector/gdevpdf.c. A remote attacker can pass specially crafted file to the application and perform a denial of service (DoS) attack.
Affected software
GhostPDL
Debian Linux
openEuler
Ubuntu
Anolis OS
ghostscript-tools-dvipdf
ghostscript-devel
ghostscript-debugsource
ghostscript-debuginfo
ghostscript
ghostscript-help
ghostscript (Ubuntu package)
ghostscript (Debian package)
ghostscript-doc
libgs
ghostscript-tools-printing
ghostscript-gtk
ghostscript-x11
ghostscript-tools-fonts
libgs-devel
Debian Linux
openEuler
Ubuntu
Anolis OS
ghostscript-tools-dvipdf
ghostscript-devel
ghostscript-debugsource
ghostscript-debuginfo
ghostscript
ghostscript-help
ghostscript (Ubuntu package)
ghostscript (Debian package)
ghostscript-doc
libgs
ghostscript-tools-printing
ghostscript-gtk
ghostscript-x11
ghostscript-tools-fonts
libgs-devel
How to mitigate CVE-2025-7462
Install update from vendor's website.
ghostscript-tools-dvipdf - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript-devel - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript-debugsource - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript-debuginfo - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript-help - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript (Ubuntu package) - addressed in versions 9.55.0~dfsg1-0ubuntu5.13, 10.02.1~dfsg1-0ubuntu7.8, 10.05.0dfsg1-0ubuntu1.2
ghostscript (Debian package) - addressed in versions 10.0.0~dfsg-11+deb12u8, 10.05.1~dfsg-1+deb13u1
ghostscript-doc - update to 10.05.1-5
libgs - update to 10.05.1-5
ghostscript-tools-printing - update to 10.05.1-5
ghostscript-gtk - update to 10.05.1-5
ghostscript-tools-dvipdf - update to 10.05.1-5
ghostscript-x11 - update to 10.05.1-5
ghostscript-tools-fonts - update to 10.05.1-5
ghostscript - update to 10.05.1-5
libgs-devel - update to 10.05.1-5
ghostscript-devel - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript-debugsource - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript-debuginfo - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript-help - addressed in versions 9.52-26, 9.55.0-23, 9.56.1-19, 9.56.1-22
ghostscript (Ubuntu package) - addressed in versions 9.55.0~dfsg1-0ubuntu5.13, 10.02.1~dfsg1-0ubuntu7.8, 10.05.0dfsg1-0ubuntu1.2
ghostscript (Debian package) - addressed in versions 10.0.0~dfsg-11+deb12u8, 10.05.1~dfsg-1+deb13u1
ghostscript-doc - update to 10.05.1-5
libgs - update to 10.05.1-5
ghostscript-tools-printing - update to 10.05.1-5
ghostscript-gtk - update to 10.05.1-5
ghostscript-tools-dvipdf - update to 10.05.1-5
ghostscript-x11 - update to 10.05.1-5
ghostscript-tools-fonts - update to 10.05.1-5
ghostscript - update to 10.05.1-5
libgs-devel - update to 10.05.1-5
External References
Related Security Bulletins
- Denial of service in Artifex GhostPDL
- Debian update for ghostscript
- Ubuntu update for ghostscript
- Anolis OS update for ghostscript
- openEuler 22.03 LTS SP4 update for ghostscript
- openEuler 24.03 LTS SP1 update for ghostscript
- openEuler 20.03 LTS SP4 update for ghostscript
- openEuler 24.03 LTS SP3 update for ghostscript
- openEuler 24.03 LTS SP4 update for ghostscript