Version in base suite: 10.05.1~dfsg-1+deb13u1 Version in overlay suite: 10.05.1~dfsg-1+deb13u2 Base version: ghostscript_10.05.1~dfsg-1+deb13u2 Target version: ghostscript_10.05.1~dfsg-1+deb13u3 Base file: /srv/ftp-master.debian.org/ftp/pool/main/g/ghostscript/ghostscript_10.05.1~dfsg-1+deb13u2.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/g/ghostscript/ghostscript_10.05.1~dfsg-1+deb13u3.dsc changelog | 12 + patches/0006_PostScript-interpreter-don-t-permit-local-inside-glo.patch | 113 ++++++++++ patches/0007_graphics-library-Shadings-with-arrays-of-Functions-v.patch | 70 ++++++ patches/0008_pdfwrite-bound-check-control-stack-in-type-1-2-font-.patch | 41 +++ patches/series | 3 5 files changed, 239 insertions(+) dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpvkn15pxn/ghostscript_10.05.1~dfsg-1+deb13u2.dsc: no acceptable signature found dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpvkn15pxn/ghostscript_10.05.1~dfsg-1+deb13u3.dsc: no acceptable signature found diff -Nru ghostscript-10.05.1~dfsg/debian/changelog ghostscript-10.05.1~dfsg/debian/changelog --- ghostscript-10.05.1~dfsg/debian/changelog 2026-09-23 12:26:54.000000000 +0000 +++ ghostscript-10.05.1~dfsg/debian/changelog 2026-10-08 19:45:14.000000000 +0000 @@ -1,3 +1,15 @@ +ghostscript (10.05.1~dfsg-1+deb13u3) trixie-security; urgency=high + + * Non-maintainer upload by the Security Team. + * PostScript interpreter - don't permit local inside global storage + (CVE-2026-101258) + * graphics library - Shadings with arrays of Functions, validate 1-out + (CVE-2026-101258) + * pdfwrite - bound check control stack in type 1->2 font conversion + (CVE-2026-103226) + + -- Salvatore Bonaccorso Thu, 08 Oct 2026 21:45:14 +0200 + ghostscript (10.05.1~dfsg-1+deb13u2) trixie-security; urgency=high * Non-maintainer upload by the Security Team. diff -Nru ghostscript-10.05.1~dfsg/debian/patches/0006_PostScript-interpreter-don-t-permit-local-inside-glo.patch ghostscript-10.05.1~dfsg/debian/patches/0006_PostScript-interpreter-don-t-permit-local-inside-glo.patch --- ghostscript-10.05.1~dfsg/debian/patches/0006_PostScript-interpreter-don-t-permit-local-inside-glo.patch 1970-01-01 00:00:00.000000000 +0000 +++ ghostscript-10.05.1~dfsg/debian/patches/0006_PostScript-interpreter-don-t-permit-local-inside-glo.patch 2026-10-08 19:37:41.000000000 +0000 @@ -0,0 +1,113 @@ +From: Ken Sharp +Date: Wed, 24 Jun 2026 09:28:01 +0100 +Subject: PostScript interpreter - don't permit local inside global storage +Origin: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=9d8b70ad1301c9993155dcf53401df3eac14fa4f +Bug: https://bugs.ghostscript.com/show_bug.cgi?id=709461 +Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-101258 + +Bug #709461 "Use-after-free in procedure-source filter state across `restore` (`psi/zfproc.c`)" + +The problem is that the C code stores a reference to a PostScript +string object, but does not check the allocation space. If the owner of +the C structure is allocated in global VM, and the string is allocated +in local VM, then the string can be restored away while the structure +stil holds a pointer to it. When we reclaim memory this causes a crash. + +From a spec perspective there's no reason to retain a pointer to a local +object in a global object, its just an implementation detail. Just to +be sure I ran the file on Distiller and that has no problems. + +So in this commit; if the 'file' object (which owns the structure) is +not in local VM, and the string returned by the procedural data source +is in local VM, then make a copy of the string in global VM. This +avoids any potential problems at the cost of using extra memory. + +This issue was reported by 'Rick de Jager '. +--- + psi/zfproc.c | 47 ++++++++++++++++++++++++++++++++++++++++++++++- + 1 file changed, 46 insertions(+), 1 deletion(-) + +diff --git a/psi/zfproc.c b/psi/zfproc.c +index 4917236a5bb7..259c1aa7e7fd 100644 +--- a/psi/zfproc.c ++++ b/psi/zfproc.c +@@ -1,4 +1,4 @@ +-/* Copyright (C) 2001-2023 Artifex Software, Inc. ++/* Copyright (C) 2001-2026 Artifex Software, Inc. + All Rights Reserved. + + This software is provided AS-IS with no warranty, either express or +@@ -124,6 +124,30 @@ s_proc_set_defaults(stream_state * st) + make_null(&ss->data); + } + ++static int s_proc_copy_string(i_ctx_t * i_ctx_p, ref *dest, ref *src, uint mem) ++{ ++ int code = 0; ++ uint saved_space = avm_local; ++ ++ saved_space = imemory_space(iimemory); ++ ++ if (imemory_space(iimemory) != mem) ++ ialloc_set_space(idmemory, mem); ++ ++ code = gs_alloc_string_ref(iimemory, dest, 0, r_size(src), "copy_cspace_string"); ++ ++ if (imemory_space(iimemory) != saved_space) ++ ialloc_set_space(idmemory, saved_space); ++ ++ if (code < 0) ++ return code; ++ ++ r_copy_attrs(dest, a_all, src); ++ ++ memcpy(dest->value.bytes, src->value.bytes, r_size(src)); ++ return 0; ++} ++ + /* ---------------- Read streams ---------------- */ + + /* Forward references */ +@@ -220,11 +244,23 @@ s_proc_read_continue(i_ctx_t *i_ctx_p) + os_ptr opbuf = op - 1; + stream *ps; + stream_proc_state *ss; ++ uint s1, s2; + + check_file(ps, op); + check_read_type(*opbuf, t_string); + while ((ps->end_status = 0, ps->strm) != 0) + ps = ps->strm; ++ s1 = r_space(op); ++ s2 = r_space(opbuf); ++ if (!r_is_local(op) && r_is_local(opbuf)) { ++ ref copy; ++ int code = 0; ++ ++ code = s_proc_copy_string(i_ctx_p, ©, opbuf, r_space(op)); ++ if (code < 0) ++ return code; ++ *opbuf = copy; ++ } + ss = (stream_proc_state *) ps->state; + ss->data = *opbuf; + ss->index = 0; +@@ -359,6 +395,15 @@ s_proc_write_continue(i_ctx_t *i_ctx_p) + ps = ps->strm; + } + ps->end_status = 0; ++ if (!r_is_local(op) && r_is_local(opbuf)) { ++ ref copy; ++ int code = 0; ++ ++ code = s_proc_copy_string(i_ctx_p, ©, opbuf, r_space(op)); ++ if (code < 0) ++ return code; ++ *opbuf = copy; ++ } + ss = (stream_proc_state *) ps->state; + ss->data = *opbuf; + ss->index = 0; +-- +2.55.0 + diff -Nru ghostscript-10.05.1~dfsg/debian/patches/0007_graphics-library-Shadings-with-arrays-of-Functions-v.patch ghostscript-10.05.1~dfsg/debian/patches/0007_graphics-library-Shadings-with-arrays-of-Functions-v.patch --- ghostscript-10.05.1~dfsg/debian/patches/0007_graphics-library-Shadings-with-arrays-of-Functions-v.patch 1970-01-01 00:00:00.000000000 +0000 +++ ghostscript-10.05.1~dfsg/debian/patches/0007_graphics-library-Shadings-with-arrays-of-Functions-v.patch 2026-10-08 19:42:14.000000000 +0000 @@ -0,0 +1,70 @@ +From: Ken Sharp +Date: Thu, 25 Jun 2026 13:51:51 +0100 +Subject: graphics library - Shadings with arrays of Functions, validate 1-out +Origin: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=3d8a1db60895493d73aeef89903d34da9837bc0a +Bug: https://bugs.ghostscript.com/show_bug.cgi?id=709462 +Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-101258 + +Bug #709462 "Ghostscript: Heap buffer overflow (OOB write) via array-wrapped shading `/Function` (`base/gsfunc3.c`)" + +The basic problem is that the shading checks for arrays of functions are +only checking to see if the number of functions in the array matches +the number of colour space ocmponents. If the functions are not 1-in, +1 out (or for type 1 shadings only; 2-in, 1 out) then the evaluation +of the function could overrun the output buffer. + +We don't actually need to check the total number of output components, +because the only valid values are 'n' 1-in, 1-out (or 2-in, 1 out) +functions; the 1-in (or 2-in) n-out case is always a single function. + +We already check (in effect) that the number of functions in the array +matches the colour space so all we need to add is a check that the +number of input components matches (1 or 2) and the number of output +components is always 1, for each function. + +This bug was reported by 'Rick de Jager ' +--- + base/gsshade.c | 16 +++++++++++++++- + 1 file changed, 15 insertions(+), 1 deletion(-) + +diff --git a/base/gsshade.c b/base/gsshade.c +index b4379f96bd35..436dc627d08e 100644 +--- a/base/gsshade.c ++++ b/base/gsshade.c +@@ -1,4 +1,4 @@ +-/* Copyright (C) 2001-2023 Artifex Software, Inc. ++/* Copyright (C) 2001-2026 Artifex Software, Inc. + All Rights Reserved. + + This software is provided AS-IS with no warranty, either express or +@@ -31,6 +31,7 @@ + #include "gxshade4.h" + #include "gzpath.h" + #include "gzcpath.h" ++#include "gsfunc3.h" + + /* ================ Initialize shadings ================ */ + +@@ -78,6 +79,19 @@ check_CBFD(const gs_shading_params_t * params, + if (function != 0) { + if (function->params.m != m || function->params.n != ncomp) + return_error(gs_error_rangecheck); ++ if (function->head.type == function_type_ArrayedOutput) { ++ /* If the Function member is an array it must contain either n 1-in, 1-out function dictionaries ++ * or (type 1, function-based shadings) n 2-in, 1-out function dictionaries. Either way all the ++ * functions have to have a single output, so we need to check that. ++ */ ++ int i = 0; ++ gs_function_AdOt_params_t *a_params = (gs_function_AdOt_params_t *)&function->params; ++ ++ for (i = 0; i < a_params->n;i++) { ++ if (a_params->Functions[i]->params.m != m || a_params->Functions[i]->params.n != 1) ++ return_error(gs_error_rangecheck); ++ } ++ } + /* + * The Adobe documentation says that the function's domain must + * be a superset of the domain defined in the shading dictionary. +-- +2.55.0 + diff -Nru ghostscript-10.05.1~dfsg/debian/patches/0008_pdfwrite-bound-check-control-stack-in-type-1-2-font-.patch ghostscript-10.05.1~dfsg/debian/patches/0008_pdfwrite-bound-check-control-stack-in-type-1-2-font-.patch --- ghostscript-10.05.1~dfsg/debian/patches/0008_pdfwrite-bound-check-control-stack-in-type-1-2-font-.patch 1970-01-01 00:00:00.000000000 +0000 +++ ghostscript-10.05.1~dfsg/debian/patches/0008_pdfwrite-bound-check-control-stack-in-type-1-2-font-.patch 2026-10-08 19:38:16.000000000 +0000 @@ -0,0 +1,41 @@ +From: Ken Sharp +Date: Tue, 25 Aug 2026 14:33:48 +0100 +Subject: pdfwrite - bound check control stack in type 1->2 font conversion +Origin: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=cbdc86cc7a95c792baae3a15c7acf59b95fbcd5c +Bug: https://bugs.ghostscript.com/show_bug.cgi?id=709672 +Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-103226 + +Bug #709672 "Stack buffer overflow in gdevpsfx.c type1_callsubr(): unbounded ipstack push in pdfwrite Type 1->2 font converter (all versions since 8.00, unfixed in master)" + +A deeply nested subr could fall off the end of the control stack. Check +the control stack before handling the subr by using the defined macro. + +Reported by lanlanwhh + +This differs from the suggested fix in the bug report by doing the check +in the main interpreter control loop, not the callsubr function. Which +is why the commit is not attributed to lanlanwh, if the fix is wrong +then its my responsibility, not theirs. + +There is nothing wrong per se with the proposed patch, but this matches +the 'normal' pattern for font parsing in our code. +--- + devices/vector/gdevpsfx.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/devices/vector/gdevpsfx.c b/devices/vector/gdevpsfx.c +index 8aaa3df1c567..cc785548366a 100644 +--- a/devices/vector/gdevpsfx.c ++++ b/devices/vector/gdevpsfx.c +@@ -237,6 +237,8 @@ type1_next(gs_type1_state *pcis) + case c_callsubr: + if (csp + 1 - &pcis->ostack[0] < 1) + return_error(gs_error_invalidfont); ++ /* Check there is space available on the control stack */ ++ CS_CHECK_IPSTACK(ipsp + 1, pcis->ipstack); + code = type1_callsubr(pcis, fixed2int_var(*csp) + + pcis->pfont->data.subroutineNumberBias); + if (code < 0) +-- +2.55.0 + diff -Nru ghostscript-10.05.1~dfsg/debian/patches/series ghostscript-10.05.1~dfsg/debian/patches/series --- ghostscript-10.05.1~dfsg/debian/patches/series 2026-09-23 12:25:06.000000000 +0000 +++ ghostscript-10.05.1~dfsg/debian/patches/series 2026-10-08 19:44:23.000000000 +0000 @@ -3,6 +3,9 @@ 0003_pdfwrite-avoid-buffer-overrun.patch 0004_OpenJPEG-Fix-overreading-bytes-in-some-conditions.patch 0005_PS-interpreter-validate-operands-to-.putgstringcopy.patch +0006_PostScript-interpreter-don-t-permit-local-inside-glo.patch +0007_graphics-library-Shadings-with-arrays-of-Functions-v.patch +0008_pdfwrite-bound-check-control-stack-in-type-1-2-font-.patch 1004_enable_spot_devices.patch 1005_simplify_ps2ascii.patch 2001_docdir_fix_for_debian.patch