Null Pointer Dereference in Artifex MuPDF Affects PDF Xref Loading
CVE-2026-92413
Key Information:
Badges
What is CVE-2026-92413?
A vulnerability has been identified in Artifex MuPDF affecting the PDF Xref Loading functionality. The flaw occurs in the 'pdf_open_filter' function within the 'pdf-stream.c' component. An attacker can exploit this vulnerability by executing a crafted manipulation, potentially leading to a null pointer dereference. This attack can be executed remotely and poses a risk to systems running the affected versions of the software. A patch has been released to address this issue, and it is strongly recommended that users apply it promptly to mitigate any potential exploitation risks.
Affected Version(s)
MuPDF b6d17493700c621c0e70036980a6ebd06d2202c9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved