Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103226— Artifex Ghostscript Pdfwrite gdevpsfx.c type1_callsubr stack-based overflow

Quick assessment

Affected
Artifex Ghostscript
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Artifex Ghostscript 10.09.0 及更早版本中发现了一个漏洞。该漏洞位于 Pdfwrite 组件的文件 中的函数 。通过操纵输入,可触发基于栈的缓冲区溢出漏洞。该攻击可被远程利用,且已有公开的利用代码(exploit)存在,可能被恶意使用。建议安装补丁以修复此问题。官方已实施解决方案:“我选择采用略有不同的修复方式,即在字体解析循环中使用已定义的宏,而不是在 callsubr 函数中直接使用,因为这种方式更符合‘常规’使用模式。”

CVSS 6.3 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103226

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Artifex Ghostscript Pdfwrite gdevpsfx.c type1_callsubr stack-based overflow
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: "I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage."
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
栈缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Artifex Ghostscript 10.09 cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-103226

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103226

请登录查看更多情报信息。

Other References for CVE-2026-103226 (7)

IV. Related Vulnerabilities

V. Comments for CVE-2026-103226

No comments yet


Leave a comment