Back

MEDIUM

Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds

Published Apr 28, 2026

Description

A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as Low impact. The out-of-bounds read in Artifex MuPDF's CFF Index Handler requires local user access to exploit, limiting its potential for widespread impact on Red Hat systems. Successful exploitation could lead to information disclosure from memory.

Red Hat mitigation

Users should avoid opening untrusted or malicious PDF documents with applications that utilize the MuPDF library. If the `mupdf` package is not essential for system operation, consider removing it to eliminate the attack surface.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Apr 28, 2026
Updated May 5, 2026
Reserved Apr 27, 2026
CISA Vulnrichment
Updated Apr 29, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 28, 2026