
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25556 is a double-free vulnerability (CWE-415) in Artifex MuPDF versions 1.23.0 through 1.27.0, affecting the fz_fill_pixmap_from_display_list() function during barcode decoding. When a rendering-time exception occurs, the function incorrectly frees a caller-owned fz_pixmap pointer in its error handling path, and the caller (e.g., fz_decode_barcode_from_display_list) also frees the same pointer during cleanup, resulting in a double-free condition. The vulnerability was published on February 6, 2026, with a patch committed on February 24, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 5.9 (Medium) (Red Hat CVE, VulnCheck Advisory).
The root cause is a double-free memory error (CWE-415) in MuPDF's fz_fill_pixmap_from_display_list() function. The function accepts a caller-owned fz_pixmap pointer and, upon encountering an exception during display list rendering, incorrectly calls fz_drop_pixmap() in its own error handling path before rethrowing the exception. The calling function — specifically the barcode decoding path in fz_decode_barcode_from_display_list — then also calls fz_drop_pixmap() during its own cleanup, resulting in the same memory being freed twice. This heap corruption can be triggered by supplying crafted input (e.g., a malformed document or barcode) that induces a rendering-time error, and only affects applications that have barcode decoding enabled. A bug report and patch commit are publicly available (Ghostscript Bug Tracker, MuPDF Commit).
Successful exploitation results in heap corruption and process crashes, leading to a denial-of-service (DoS) condition. There is no known confidentiality or integrity impact — the vulnerability's primary consequence is availability loss for applications relying on MuPDF's barcode decoding functionality. Applications processing untrusted documents (e.g., PDF viewers, document conversion services) with barcode decoding enabled are at risk of being crashed by a crafted input file (VulnCheck Advisory, Red Hat CVE).
A proof-of-concept is publicly available via the Ghostscript bug tracker, but there is no evidence of active in-the-wild exploitation at this time. The vulnerability is network-exploitable without authentication, though it requires the target application to have barcode decoding enabled and to process attacker-controlled input. The EPSS score is approximately 0.042%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available in Nessus (IDs 298282, 299733) and Qualys (IDs 288165, 288170) (Ghostscript Bug Tracker, Tenable).
fz_fill_pixmap_from_display_list() during barcode decoding.fz_fill_pixmap_from_display_list() to free the pixmap in its error path; the caller then frees it again, corrupting the heap.mupdf, zathura, pymupdf-based services) when processing document files.free(): double free detected, malloc(): memory corruption) originating from MuPDF library calls; crash dumps referencing fz_fill_pixmap_from_display_list or fz_decode_barcode_from_display_list in stack traces.The primary remediation is to upgrade MuPDF to version 1.27.1 or later, which includes the fix committed on February 24, 2026 (commit d4743b6092d513321c23c6f7fe5cff87cde043c1). Linux distribution packages for openSUSE and Fedora (42 and 43) have been updated to include the patched version. If immediate patching is not feasible, disable barcode decoding functionality in applications using MuPDF, and implement network-level controls to restrict untrusted input to barcode processing services. Monitor affected systems for process crashes that may indicate exploitation attempts (MuPDF Commit, Red Hat CVE).
Red Hat has acknowledged the vulnerability and published a CVE advisory page. Linux distributions including openSUSE and Fedora (42 and 43) have issued security updates for MuPDF and related packages (e.g., zathura-pdf-mupdf, python-pymupdf). Coverage has appeared on Linux security news aggregators and community blogs, with general consensus that the risk is moderate given the DoS-only impact and the requirement for barcode decoding to be enabled (Red Hat CVE, VulnCheck Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."