Version in base suite: 10.05.1~dfsg-1+deb13u1 Base version: ghostscript_10.05.1~dfsg-1+deb13u1 Target version: ghostscript_10.05.1~dfsg-1+deb13u2 Base file: /srv/ftp-master.debian.org/ftp/pool/main/g/ghostscript/ghostscript_10.05.1~dfsg-1+deb13u1.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/g/ghostscript/ghostscript_10.05.1~dfsg-1+deb13u2.dsc changelog | 8 + patches/0004_OpenJPEG-Fix-overreading-bytes-in-some-conditions.patch | 71 ++++++++++ patches/0005_PS-interpreter-validate-operands-to-.putgstringcopy.patch | 69 +++++++++ patches/series | 2 4 files changed, 150 insertions(+) dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpg3rpbbtr/ghostscript_10.05.1~dfsg-1+deb13u1.dsc: no acceptable signature found dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpg3rpbbtr/ghostscript_10.05.1~dfsg-1+deb13u2.dsc: no acceptable signature found diff -Nru ghostscript-10.05.1~dfsg/debian/changelog ghostscript-10.05.1~dfsg/debian/changelog --- ghostscript-10.05.1~dfsg/debian/changelog 2025-10-05 07:09:15.000000000 +0000 +++ ghostscript-10.05.1~dfsg/debian/changelog 2026-09-23 12:26:54.000000000 +0000 @@ -1,3 +1,11 @@ +ghostscript (10.05.1~dfsg-1+deb13u2) trixie-security; urgency=high + + * Non-maintainer upload by the Security Team. + * OpenJPEG - Fix overreading bytes in some conditions (CVE-2026-39919) + * PS interpreter - validate operands to .putgstringcopy + + -- Salvatore Bonaccorso Wed, 23 Sep 2026 14:26:54 +0200 + ghostscript (10.05.1~dfsg-1+deb13u1) trixie-security; urgency=high * Non-maintainer upload by the Security Team. diff -Nru ghostscript-10.05.1~dfsg/debian/patches/0004_OpenJPEG-Fix-overreading-bytes-in-some-conditions.patch ghostscript-10.05.1~dfsg/debian/patches/0004_OpenJPEG-Fix-overreading-bytes-in-some-conditions.patch --- ghostscript-10.05.1~dfsg/debian/patches/0004_OpenJPEG-Fix-overreading-bytes-in-some-conditions.patch 1970-01-01 00:00:00.000000000 +0000 +++ ghostscript-10.05.1~dfsg/debian/patches/0004_OpenJPEG-Fix-overreading-bytes-in-some-conditions.patch 2026-09-23 08:31:06.000000000 +0000 @@ -0,0 +1,71 @@ +From: Ken Sharp +Date: Mon, 24 Aug 2026 16:07:23 +0100 +Subject: OpenJPEG - Fix overreading bytes in some conditions. +Origin: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=0a8bf88e39db07b0751a58d6ec1cf992073e4dc1 +Bug: https://bugs.ghostscript.com/show_bug.cgi?id=709666 +Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-39919 + +Bug #709666 "Heap buffer overflow in the JPEG 2000 (JPXDecode) output adapter via component subsampling mismatch (base/sjpx_openjpeg.c)" + +If we have more than one component, and the components are not the +same scale factor, and the number of bits is less than 8, then we would +run round a loop reading 'state->width' samples of data to the output. + +The problem, of course, is that if the BPS is less than 8, we don't +want to read that many bytes, just that many samples. + +Fixed here by incrementing the sample count in the inner loop, so that +we correctly count the number of samples. + +For completeness, also check the number of samples in side the inner +loop so that we don't overread. We do need to run round the loop as +many times as there are samples in a byte, because that pushes the +data read so far to the left so that any unread data is at the right of +the byte. + +This exposed an interesting bug in a regression file. It hits the +same scale loop, but has bps equal to 10. This resulted in us reading +no data in the old code, but in the new code reading way too much. + +Added a guard in decode_image to error out on images which have BPS +which we don't support. + +The original issue was reported by Alex Thomas +of Wordfence Argus (AI). +--- + base/sjpx_openjpeg.c | 10 +++++++--- + 1 file changed, 7 insertions(+), 3 deletions(-) + +--- a/base/sjpx_openjpeg.c ++++ b/base/sjpx_openjpeg.c +@@ -490,6 +490,9 @@ static int decode_image(stream_jpxd_stat + if (state->bpp == 12) + state->bpp = 16; + ++ if (state->bpp != 1 && state->bpp != 2 && state->bpp != 4 && state->bpp != 8 && state->bpp != 16) ++ return ERRC; ++ + /* calculate total data */ + rowbytes = (state->width*state->bpp*state->out_numcomps+7)/8; + state->totalbytes = (ulong)rowbytes*state->height; +@@ -654,16 +657,17 @@ static int process_one_trunk(stream_jpxd + int ppbyte1 = 8/state->bpp; + /* sampling required */ + /* only grayscale can have such bit-depth, also shift_bit = 0, bpp < 8 */ +- for (i = 0; i < state->width; i++) ++ for (i = 0; i < state->width; ) + { +- for (b=0; bimage->comps[compno].dx; + int dy = state->image->comps[compno].dy; + int w = state->image->comps[compno].w; + int in_offset_scaled = (y_offset/dy * w) + i / dx; + bt = bt<bpp; +- bt += state->image->comps[compno].data[in_offset_scaled] + state->sign_comps[compno]; ++ if (i < state->width) ++ bt += state->image->comps[compno].data[in_offset_scaled] + state->sign_comps[compno]; + } + *row++ = bt; + } diff -Nru ghostscript-10.05.1~dfsg/debian/patches/0005_PS-interpreter-validate-operands-to-.putgstringcopy.patch ghostscript-10.05.1~dfsg/debian/patches/0005_PS-interpreter-validate-operands-to-.putgstringcopy.patch --- ghostscript-10.05.1~dfsg/debian/patches/0005_PS-interpreter-validate-operands-to-.putgstringcopy.patch 1970-01-01 00:00:00.000000000 +0000 +++ ghostscript-10.05.1~dfsg/debian/patches/0005_PS-interpreter-validate-operands-to-.putgstringcopy.patch 2026-09-23 12:24:52.000000000 +0000 @@ -0,0 +1,69 @@ +From: Ken Sharp +Date: Wed, 2 Sep 2026 12:04:15 +0100 +Subject: PS interpreter - validate operands to .putgstringcopy +Origin: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=1484854e0c8ddfda1baa4ad4cd965b8a9790aa81 +Bug: https://bugs.ghostscript.com/show_bug.cgi?id=709684 + +Bug #709684 "Type 1 font-loader `.forceput` save/restore UAF yields native read/write and controlled dispatch/RCE under `-dSAFER`" + +Effectively another case of recovering .forceput, in this case by +causing an error and then having the error handler use it. + +We are in the process of eliminating, or at least absolutely minimising, +the use of .forceput. Ideally we want to remove it completely precisely +to avoid this sort of thing. Unfortunately that's still a work in +progress; it isn't easy to undo 30 years worth of assumptions in the +code. + +For now this prevents the problem by ensuring that the operands are the +correct types, which prevents the error executing 'copy' and so avoids +the custom error handler managing to execute .forceput. + +This issue was reported by Paulos Yibelo +--- + Resource/Init/gs_fonts.ps | 25 ++++++++++++++++--------- + 1 file changed, 16 insertions(+), 9 deletions(-) + +diff --git a/Resource/Init/gs_fonts.ps b/Resource/Init/gs_fonts.ps +index 5b46ef1f558e..5420431c7dab 100644 +--- a/Resource/Init/gs_fonts.ps ++++ b/Resource/Init/gs_fonts.ps +@@ -1,4 +1,4 @@ +-% Copyright (C) 2001-2023 Artifex Software, Inc. ++% Copyright (C) 2001-2026 Artifex Software, Inc. + % All Rights Reserved. + % + % This software is provided AS-IS with no warranty, either express or +@@ -1024,14 +1024,21 @@ $error /SubstituteFont { } put + + % any user of .putgstringcopy must use bind and executeonly + /.putgstringcopy % .putgstringcopy - +-{ 2 index gcheck currentglobal +- 2 copy eq { +- pop pop .forceput +- } executeonly { +- 5 1 roll setglobal +- dup length string copy +- .forceput setglobal +- } executeonly ifelse ++{ ++ % Check operand types ++ dup type /stringtype eq 2 index type /nametype eq and 3 index type /dicttype eq and { ++ 2 index gcheck currentglobal ++ 2 copy eq { ++ pop pop .forceput ++ } executeonly { ++ 5 1 roll setglobal ++ dup length string copy ++ .forceput setglobal ++ } executeonly ifelse ++ } ++ { ++ /.putgstringcopy cvx /typecheck signalerror ++ } ifelse + } .forcebind odef % must be bound and hidden for .forceput + + /.loadfontloop { % .loadfontloop +-- +2.55.0 + diff -Nru ghostscript-10.05.1~dfsg/debian/patches/series ghostscript-10.05.1~dfsg/debian/patches/series --- ghostscript-10.05.1~dfsg/debian/patches/series 2025-10-05 07:07:59.000000000 +0000 +++ ghostscript-10.05.1~dfsg/debian/patches/series 2026-09-23 12:25:06.000000000 +0000 @@ -1,6 +1,8 @@ 0001_CVE-2025-7462.patch 0002_pdfwrite-bounds-check-some-strings.patch 0003_pdfwrite-avoid-buffer-overrun.patch +0004_OpenJPEG-Fix-overreading-bytes-in-some-conditions.patch +0005_PS-interpreter-validate-operands-to-.putgstringcopy.patch 1004_enable_spot_devices.patch 1005_simplify_ps2ascii.patch 2001_docdir_fix_for_debian.patch