Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. Ghostscript's -dSAFER sandbox can be bypassed by a crafted PostScript document that chains two memory-safety bugs to achieve arbitrary command execution in the Ghostscript process context. Bug 1 (procedure-stream use-after-free, psi/zfproc.c): In s_proc_read_continue, ss->data = *opbuf (line 323) stores a procedure-returned string without a save/restore write barrier. A global procedure stream can retain a reference to a local-VM string freed by restore, leaving a dangling pointer. Subsequent reads leak heap contents (ASLR defeat). GhostPDL 10.09.0 adds cross-space copy (s_proc_copy_string, lines 313-321) and save-ID tracking (s_proc_record_data / s_proc_data_valid); the public PoC works through upstream 10.07.1 on x86-64. Bug 2 (Type 5 shading OOB write, base/gsshade.c, base/gsfunc3.c, psi/zshade.c): check_CBFD validated only the ArrayedOutput wrapper n field. fn_AdOt_evaluate (gsfunc3.c:643-648) calls gs_function_evaluate for each sub-function at out+i, assuming one output per sub-function. A one-element Function array wrapping a multi-output sub-function passes validation but overruns the color buffer. GhostPDL 10.09.0 check_CBFD (gsshade.c:82-93) requires each sub-function to declare exactly one output. Exploit chain: (1) UAF leak for code and heap pointers; (2) shading OOB write corrupts a SubFileDecode stream for arbitrary read; (3) scan gs_lib_ctx_core_t for path_control_active; (4) write 0 to path_control_active; (5) %pipe% executes a shell command. Enforcement bypass is in gp_validate_path_len (base/gpmisc.c:1048-1051) when path_control_active == 0. Trigger: malicious .ps/.eps (or embedded in ODF/DOCX/SVG) processed with a raster device (not nullpage/bbox/pdfwrite). Public PoC: https://github.com/v12-security/pocs/tree/main/ghostscript (V12 Security, BSides Canberra 2026). Reported upstream 10.00.0 through 10.07.1 on x86-64 Linux; layout constants are architecture-specific. Red Hat verification: On RHEL 10.2 x86_64, ghostscript-10.02.1-16.el10 (CentOS Stream 10) and ghostscript-10.02.1-16.el10_0 (UBI 10) ran attacker command under -dSAFER (gs exit 139). SELinux enforcing did not block unconfined_t or initrc_t; container_t still launched a shell (AVC denied proof-file write only). RHEL 8/9 builds not dynamically retested; impact under analysis. Affected (upstream): Ghostscript 10.00.0 through at least 10.07.1 (exploit); underlying bugs may affect older branches shipped in RHEL 8/9. Fix: No Red Hat package fix yet. Upstream GhostPDL 10.09.0 source contains apparent fixes for both primitives; backport assessment pending. Reporter: Akiyoshi Kurita (PSIRTSUPT submitter); research by V12 Security. PSIRT ticket: PSIRTSUPT-24732 OSIM: OSIM-119279 / CVE-2026-101258 (embargoed).