CVE-2025-59798
Ghostscript vulnerability analysis and mitigation

Overview

CVE-2025-59798 is a stack-based buffer overflow vulnerability in Artifex Ghostscript affecting all versions through 10.05.1. The flaw resides in the pdf_write_cmap function within devices/vector/gdevpdtw.c, which handles PDF CMap (character mapping) writing operations. It was published on September 22, 2025, with a patch commit made available on September 25, 2025. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, with availability impact rated High and no confidentiality or integrity impact (Red Hat Advisory, Ghostscript Commit).

Technical details

The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow), occurring in the pdf_write_cmap function in devices/vector/gdevpdtw.c within Ghostscript's PDF vector device subsystem. An attacker with local access can supply a crafted input (e.g., a malicious PDF or PostScript file) that triggers the overflow during CMap processing, potentially corrupting stack memory. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity. A bug report and the fixing commit are publicly available (Ghostscript Bug Tracker, Ghostscript Commit).

Impact

Successful exploitation of this vulnerability primarily impacts availability, as the stack-based buffer overflow can cause Ghostscript to crash or become unresponsive, resulting in a denial-of-service condition. There is no assessed confidentiality impact, and integrity impact is considered minimal. Systems or services that rely on Ghostscript for automated document processing (e.g., print servers, document conversion pipelines) could be disrupted if an attacker can supply malicious input files (Red Hat Advisory).

Exploitability

There is no public proof-of-concept exploit code known at this time, and no evidence of in-the-wild exploitation has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term (Red Hat Advisory).

Mitigation and workarounds

Users should upgrade Ghostscript to a version beyond 10.05.1, as the patch was committed on September 25, 2025. Major Linux distributions including Ubuntu (USN-7782-1), Debian (DLA-4330-1, DSA-6024-1), SUSE (SUSE-SU-2025:4125-1, SUSE-SU-2025:4148-1), Amazon Linux 2 (ALAS2-2025-3018), and Fedora have released updated packages. Until patching is possible, administrators should restrict local access to systems running Ghostscript and avoid processing untrusted PDF or PostScript files (Ubuntu Advisory, Amazon Linux Advisory, Ghostscript Commit).

Community reactions

The vulnerability received routine coverage from Linux distribution security teams, with advisories issued by Ubuntu, Debian, SUSE, Amazon Linux, and Fedora. No notable researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking and distribution patching activity (Ubuntu Advisory).

Additional resources


SourceThis report was generated using AI

Related Ghostscript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59800MEDIUM5.5
  • Ghostscript logoGhostscript
  • ghostscript-cups
NoYesSep 22, 2025
CVE-2025-59799MEDIUM5.5
  • Ghostscript logoGhostscript
  • libgs-debuginfo
NoYesSep 22, 2025
CVE-2025-59798MEDIUM5.5
  • Ghostscript logoGhostscript
  • ghostscript-gtk
NoYesSep 22, 2025
CVE-2025-59801MEDIUM4.3
  • Ghostscript logoGhostscript
  • ghostscript-devel
NoYesSep 22, 2025
CVE-2026-6192LOW1.9
  • Ghostscript logoGhostscript
  • blender
NoYesApr 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management