|
|
Log in / Subscribe / Register

SUSE alert SUSE-SU-2026:21363-1 (ghostscript)

From:  SLE-SECURITY-UPDATES <null@suse.de>
To:  sle-security-updates@lists.suse.com
Subject:  SUSE-SU-2026:21363-1: moderate: Security update for ghostscript
Date:  Tue, 28 Apr 2026 16:33:25 -0000
Message-ID:  <177739400514.48.4731859254742337091@9e3d0d49577d>

# Security update for ghostscript Announcement ID: SUSE-SU-2026:21363-1 Release Date: 2026-04-21T09:49:39Z Rating: moderate References: * bsc#1243701 * bsc#1245896 * bsc#1250353 * bsc#1250354 * bsc#1250355 * bsc#1257699 Cross-References: * CVE-2025-46646 * CVE-2025-48708 * CVE-2025-59798 * CVE-2025-59799 * CVE-2025-59800 * CVE-2025-59801 CVSS scores: * CVE-2025-46646 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2025-46646 ( NVD ): 4.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2025-48708 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-48708 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2025-48708 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-59798 ( SUSE ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-59798 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59798 ( NVD ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-59799 ( SUSE ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-59799 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59799 ( NVD ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-59800 ( SUSE ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-59800 ( NVD ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-59800 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59801 ( NVD ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for ghostscript fixes the following issues: Update to version 10.06.0. Security issues fixed: * CVE-2025-59800: an integer overflow can lead to a heap-based buffer overflow in ocr_line8 (bsc#1250355). * CVE-2025-59799: a large size value can cause a stack-based buffer overflow in pdfmark_coerce_dest (bsc#1250354). * CVE-2025-59798: stack-based buffer overflow in pdf_write_cmap can lead to a denial-of-service (bsc#1250353). * CVE-2025-48708: lacks of argument sanitization may lead to password disclosure (bsc#1243701). * CVE-2025-46646: mishandling of overlong utf-8 encoding in artifex ghostscript's decode_utf8 function (bsc#1257699). Other updates and bugfixes: * switch over to libalternatives for ghostscript to provide a gs variant (bsc#1245896) * Version upgrade to 10.06.0: * removes the non-standard operator "selectdevice" (cf. the entry below dated Tue Apr 1 09:56:06 UTC 2025) * Version upgrade to 10.05.1: * an overflow issue in Freetype on platforms where long is a 4 byte (rather than 8 byte) type (Microsoft Windows, for example) causing corrupted glyph rendering at higher resolutions * an issue with embedded files, affecting Zugferd format PDF creation. * broken logic in PDF Optional Content processing * potential slow down due to searching for identifiable font files * a small number of extreme edge case segmentation faults. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-602=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-602=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * ghostscript-x11-debuginfo-10.06.0-160000.1.1 * ghostscript-devel-10.06.0-160000.1.1 * ghostscript-debugsource-10.06.0-160000.1.1 * ghostscript-10.06.0-160000.1.1 * ghostscript-x11-10.06.0-160000.1.1 * ghostscript-debuginfo-10.06.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * ghostscript-x11-debuginfo-10.06.0-160000.1.1 * ghostscript-devel-10.06.0-160000.1.1 * ghostscript-debugsource-10.06.0-160000.1.1 * ghostscript-10.06.0-160000.1.1 * ghostscript-x11-10.06.0-160000.1.1 * ghostscript-debuginfo-10.06.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-46646.html * https://www.suse.com/security/cve/CVE-2025-48708.html * https://www.suse.com/security/cve/CVE-2025-59798.html * https://www.suse.com/security/cve/CVE-2025-59799.html * https://www.suse.com/security/cve/CVE-2025-59800.html * https://www.suse.com/security/cve/CVE-2025-59801.html * https://bugzilla.suse.com/show_bug.cgi?id=1243701 * https://bugzilla.suse.com/show_bug.cgi?id=1245896 * https://bugzilla.suse.com/show_bug.cgi?id=1250353 * https://bugzilla.suse.com/show_bug.cgi?id=1250354 * https://bugzilla.suse.com/show_bug.cgi?id=1250355 * https://bugzilla.suse.com/show_bug.cgi?id=1257699


Attachment: None (type=text/html)

(HTML attachment elided)


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds