CVE-2026-25556: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-25556 is a double-free vulnerability (CWE-415) in Artifex MuPDF versions 1.23.0 through 1.27.0, affecting the fz_fill_pixmap_from_display_list() function during barcode decoding. When a rendering-time exception occurs, the function incorrectly frees a caller-owned fz_pixmap pointer in its error handling path, and the caller (e.g., fz_decode_barcode_from_display_list) also frees the same pointer during cleanup, resulting in a double-free condition. The vulnerability was published on February 6, 2026, with a patch committed on February 24, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 5.9 (Medium) (Red Hat CVE, VulnCheck Advisory).

Technical details

The root cause is a double-free memory error (CWE-415) in MuPDF's fz_fill_pixmap_from_display_list() function. The function accepts a caller-owned fz_pixmap pointer and, upon encountering an exception during display list rendering, incorrectly calls fz_drop_pixmap() in its own error handling path before rethrowing the exception. The calling function — specifically the barcode decoding path in fz_decode_barcode_from_display_list — then also calls fz_drop_pixmap() during its own cleanup, resulting in the same memory being freed twice. This heap corruption can be triggered by supplying crafted input (e.g., a malformed document or barcode) that induces a rendering-time error, and only affects applications that have barcode decoding enabled. A bug report and patch commit are publicly available (Ghostscript Bug Tracker, MuPDF Commit).

Impact

Successful exploitation results in heap corruption and process crashes, leading to a denial-of-service (DoS) condition. There is no known confidentiality or integrity impact — the vulnerability's primary consequence is availability loss for applications relying on MuPDF's barcode decoding functionality. Applications processing untrusted documents (e.g., PDF viewers, document conversion services) with barcode decoding enabled are at risk of being crashed by a crafted input file (VulnCheck Advisory, Red Hat CVE).

Exploitability

A proof-of-concept is publicly available via the Ghostscript bug tracker, but there is no evidence of active in-the-wild exploitation at this time. The vulnerability is network-exploitable without authentication, though it requires the target application to have barcode decoding enabled and to process attacker-controlled input. The EPSS score is approximately 0.042%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available in Nessus (IDs 298282, 299733) and Qualys (IDs 288165, 288170) (Ghostscript Bug Tracker, Tenable).

Exploitation steps

  1. Reconnaissance: Identify applications that use MuPDF versions 1.23.0–1.27.0 with barcode decoding enabled (e.g., PDF viewers, document processing services, or web applications accepting document uploads).
  2. Craft malicious input: Create a document (e.g., a PDF) containing a barcode or display list element specifically designed to trigger a rendering-time exception within fz_fill_pixmap_from_display_list() during barcode decoding.
  3. Deliver the payload: Submit the crafted document to the target application via any supported input channel — file upload, email attachment, or network-accessible document processing endpoint.
  4. Trigger double-free: When the application processes the document and attempts barcode decoding, the rendering exception causes fz_fill_pixmap_from_display_list() to free the pixmap in its error path; the caller then frees it again, corrupting the heap.
  5. Achieve DoS: The heap corruption causes the MuPDF process to crash, resulting in a denial-of-service condition for the affected application (Ghostscript Bug Tracker, VulnCheck Advisory).

Indicators of compromise

  • Process: Unexpected crashes or segmentation faults in processes using MuPDF (e.g., mupdf, zathura, pymupdf-based services) when processing document files.
  • Logs: Application error logs showing double-free or heap corruption errors (e.g., free(): double free detected, malloc(): memory corruption) originating from MuPDF library calls; crash dumps referencing fz_fill_pixmap_from_display_list or fz_decode_barcode_from_display_list in stack traces.
  • File System: Presence of crafted PDF or document files with unusual or malformed barcode structures submitted to document processing directories.
  • Network: Repeated submission of the same or similar document files to a document processing endpoint, particularly if followed by service restarts or crashes.

Mitigation and workarounds

The primary remediation is to upgrade MuPDF to version 1.27.1 or later, which includes the fix committed on February 24, 2026 (commit d4743b6092d513321c23c6f7fe5cff87cde043c1). Linux distribution packages for openSUSE and Fedora (42 and 43) have been updated to include the patched version. If immediate patching is not feasible, disable barcode decoding functionality in applications using MuPDF, and implement network-level controls to restrict untrusted input to barcode processing services. Monitor affected systems for process crashes that may indicate exploitation attempts (MuPDF Commit, Red Hat CVE).

Community reactions

Red Hat has acknowledged the vulnerability and published a CVE advisory page. Linux distributions including openSUSE and Fedora (42 and 43) have issued security updates for MuPDF and related packages (e.g., zathura-pdf-mupdf, python-pymupdf). Coverage has appeared on Linux security news aggregators and community blogs, with general consensus that the risk is moderate given the DoS-only impact and the requirement for barcode decoding to be enabled (Red Hat CVE, VulnCheck Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

mupdf

Fixed

sid

mupdf: 1.27.0+ds1-3

Fixed

trixie

mupdf

Affected

Ubuntu

Unknown

bionic (esm-apps)

mupdf

Unknown

devel

mupdf

Unknown

focal (esm-apps)

mupdf

Unknown

jammy

mupdf

Unknown

jammy (esm-apps)

mupdf

Unknown

noble

mupdf

Unknown

noble (esm-apps)

mupdf

Unknown

resolute

mupdf

Unknown

Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management