Bug 2546645 - CVE-2026-101258 ghostscript: ghostscript: -dSAFER sandbox bypass via Type 5 shading OOB write and procedure-stream use-after-free [fedora-all]
Summary: CVE-2026-101258 ghostscript: ghostscript: -dSAFER sandbox bypass via Type 5 s...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: ghostscript
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Zdenek Dohnal
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["aaaa4a9d-b378-4256-846e-0...
Depends On:
Blocks: CVE-2026-101258
TreeView+ depends on / blocked
 
Reported: 2026-10-06 16:00 UTC by lcelant
Modified: 2026-10-06 16:00 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description lcelant 2026-10-06 16:00:07 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Ghostscript's -dSAFER sandbox can be bypassed by a crafted PostScript document that chains two memory-safety bugs to achieve arbitrary command execution in the Ghostscript process context.

Bug 1 (procedure-stream use-after-free, psi/zfproc.c): In s_proc_read_continue, ss->data = *opbuf (line 323) stores a procedure-returned string without a save/restore write barrier. A global procedure stream can retain a reference to a local-VM string freed by restore, leaving a dangling pointer. Subsequent reads leak heap contents (ASLR defeat). GhostPDL 10.09.0 adds cross-space copy (s_proc_copy_string, lines 313-321) and save-ID tracking (s_proc_record_data / s_proc_data_valid); the public PoC works through upstream 10.07.1 on x86-64.

Bug 2 (Type 5 shading OOB write, base/gsshade.c, base/gsfunc3.c, psi/zshade.c): check_CBFD validated only the ArrayedOutput wrapper n field. fn_AdOt_evaluate (gsfunc3.c:643-648) calls gs_function_evaluate for each sub-function at out+i, assuming one output per sub-function. A one-element Function array wrapping a multi-output sub-function passes validation but overruns the color buffer. GhostPDL 10.09.0 check_CBFD (gsshade.c:82-93) requires each sub-function to declare exactly one output.

Exploit chain: (1) UAF leak for code and heap pointers; (2) shading OOB write corrupts a SubFileDecode stream for arbitrary read; (3) scan gs_lib_ctx_core_t for path_control_active; (4) write 0 to path_control_active; (5) %pipe% executes a shell command. Enforcement bypass is in gp_validate_path_len (base/gpmisc.c:1048-1051) when path_control_active == 0.

Trigger: malicious .ps/.eps (or embedded in ODF/DOCX/SVG) processed with a raster device (not nullpage/bbox/pdfwrite). Public PoC: https://github.com/v12-security/pocs/tree/main/ghostscript (V12 Security, BSides Canberra 2026). Reported upstream 10.00.0 through 10.07.1 on x86-64 Linux; layout constants are architecture-specific.

Red Hat verification: On RHEL 10.2 x86_64, ghostscript-10.02.1-16.el10 (CentOS Stream 10) and ghostscript-10.02.1-16.el10_0 (UBI 10) ran attacker command under -dSAFER (gs exit 139). SELinux enforcing did not block unconfined_t or initrc_t; container_t still launched a shell (AVC denied proof-file write only). RHEL 8/9 builds not dynamically retested; impact under analysis.

Affected (upstream): Ghostscript 10.00.0 through at least 10.07.1 (exploit); underlying bugs may affect older branches shipped in RHEL 8/9.
Fix: No Red Hat package fix yet. Upstream GhostPDL 10.09.0 source contains apparent fixes for both primitives; backport assessment pending.

Reporter: Akiyoshi Kurita (PSIRTSUPT submitter); research by V12 Security.
PSIRT ticket: PSIRTSUPT-24732
OSIM: OSIM-119279 / CVE-2026-101258 (embargoed).


Note You need to log in before you can comment on or make changes to this bug.