CVE-2026-103226 | Artifex Ghostscript up to 10.09.0 Pdfwrite gdevpsfx.c type1_callsubr stack-based overflow (Bug 709672)

SecurityVulns

A vulnerability marked as critical has been reported in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow.

This vulnerability is referenced as CVE-2026-103226. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

It is suggested to install a patch to address this issue.

A solution was implemented: “I’ve chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of ‘normal’ usage.”VulDB Recent EntriesRead More