CVE-2025-59800
Ghostscript vulnerability analysis and mitigation

Overview

CVE-2025-59800 is an integer overflow vulnerability in Artifex Ghostscript through version 10.05.1, located in the ocr_begin_page function within devices/gdevpdfocr.c. The overflow leads to a heap-based buffer overflow in the ocr_line8 component. It was published on September 22, 2025, with a patch committed to the Ghostscript repository shortly after. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) with a local attack vector (Red Hat CVE, Ghostscript Commit).

Technical details

The root cause is an integer overflow (CWE-190) in the ocr_begin_page function in devices/gdevpdfocr.c, which is part of Ghostscript's PDF OCR device handling. When processing certain inputs, the integer overflow causes an undersized heap buffer to be allocated, which is subsequently overflowed during the ocr_line8 operation. Exploitation requires local access with low privileges and no user interaction. The fix was committed to the GhostPDL repository and is referenced in the Ghostscript bug tracker (Ghostscript Bug, Ghostscript Commit).

Impact

Successful exploitation of this vulnerability primarily impacts availability, as the heap-based buffer overflow can cause system instability or crashes in Ghostscript processes. Confidentiality is not impacted, and integrity impact is assessed as none under the NVD scoring. The vulnerability is locally scoped, limiting its reach to systems where an attacker already has low-privileged local access, such as shared document processing environments (Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins have been released by Nessus and Qualys for scanning purposes (Red Hat CVE, Tenable Nessus).

Mitigation and workarounds

Users should upgrade Ghostscript to a version beyond 10.05.1, as the patch has been committed to the upstream GhostPDL repository. Until an upgrade is possible, restrict access to Ghostscript processing to trusted local users only and implement strict input validation for documents processed by Ghostscript. Ubuntu has issued security notice USN-7782-1, Amazon Linux has released ALAS2-2025-3018, and Fedora and NixOS packages have also been updated (Ubuntu Advisory, Amazon Linux, Ghostscript Commit).

Community reactions

Red Hat has published a CVE advisory tracking this vulnerability, and multiple Linux distributions including Ubuntu, Amazon Linux, and Fedora have issued security updates. The Yocto Project security mailing list has discussed the issue across multiple messages. No notable researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking and patch distribution (Red Hat CVE, Ubuntu Advisory).

Additional resources


SourceThis report was generated using AI

Related Ghostscript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59800MEDIUM5.5
  • Ghostscript logoGhostscript
  • ghostscript-cups
NoYesSep 22, 2025
CVE-2025-59799MEDIUM5.5
  • Ghostscript logoGhostscript
  • libgs-debuginfo
NoYesSep 22, 2025
CVE-2025-59798MEDIUM5.5
  • Ghostscript logoGhostscript
  • ghostscript-gtk
NoYesSep 22, 2025
CVE-2025-59801MEDIUM4.3
  • Ghostscript logoGhostscript
  • ghostscript-devel
NoYesSep 22, 2025
CVE-2026-6192LOW1.9
  • Ghostscript logoGhostscript
  • blender
NoYesApr 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management