Debian Package Tracker
Register | Log in
Subscribe

mupdf

lightweight PDF viewer

Choose email to subscribe with

general
  • source: mupdf (main)
  • version: 1.27.0+ds1-6
  • maintainer: Kan-Ru Chen (陳侃如) (DMD)
  • uploaders: Daniel Echeverri [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.17.0+ds1-2
  • o-o-sec: 1.17.0+ds1-2+deb11u2
  • oldstable: 1.21.1+ds2-1+deb12u1
  • old-sec: 1.21.1+ds2-1+deb12u1
  • stable: 1.25.1+ds1-6+deb13u1
  • stable-sec: 1.25.1+ds1-6+deb13u1
  • testing: 1.27.0+ds1-6
  • unstable: 1.27.0+ds1-6
versioned links
  • 1.17.0+ds1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.17.0+ds1-2+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.21.1+ds2-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.25.1+ds1-6+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.27.0+ds1-6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libmupdf-dev
  • libmupdf27.0
  • mupdf (23 bugs: 0, 16, 7, 0)
  • mupdf-tools (2 bugs: 0, 2, 0, 0)
  • python3-mupdf
action needed
A new upstream version is available: 1.28.0 high
A new upstream version 1.28.0 is available, you should consider packaging it.
Created: 2026-05-18 Last update: 2026-07-31 17:31
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-7233: A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Created: 2026-04-28 Last update: 2026-07-26 01:20
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-7233: A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Created: 2026-04-28 Last update: 2026-07-26 01:20
3 bugs tagged patch in the BTS normal
The BTS contains patches fixing 3 bugs, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-07-31 22:00
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • libmupdf27.0 could be marked Multi-Arch: same
Created: 2026-05-18 Last update: 2026-07-31 19:01
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 1.28.0+ds1-1, distribution experimental) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit 30595cd0fc575ff4fc0d6ab24dd0cffdd1f8f379
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:53:21 2026 -0500

    Update changelog file

commit 385269cf4918468024e4625d9dd3ed9711ae2a41
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:41:24 2026 -0500

    Add flags to use system cmark-gfm library

commit 7a72021bbbcd5cb98d68f4fb2086cd424c10e748
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:39:37 2026 -0500

    Add doxygen in B-D

commit f42750c47bcec398f0defca3ce3270cc39ef6c08
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:38:02 2026 -0500

    Rename lib package to libmupdf28.0 for new soname

commit 77562e93dfa04096efd44a80c1cc54a26a4f5553
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:36:09 2026 -0500

    Install mupdf-x11-curl binary

commit 7fb182e469227507469d98e3cb37318a4fbcb2ab
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:35:28 2026 -0500

    Update clean file

commit c1d60a65db09fe475d7a7be01bd92b84fdd28340
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:29:19 2026 -0500

    Rename libmupdf27.0.install to libmupdf28.0.install

commit 2742baf8430ed4eec40edaab9b0acddd61ab6acd
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:27:22 2026 -0500

    Add new symbols file

commit 8db9de743d3cc69714de905c667ceec2ef997222
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:26:06 2026 -0500

    Remove old symbols file

commit ea57813e744b34c06aaa640d34739d26ae652793
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:21:51 2026 -0500

    Add patch to remove venv param and dont build latex doc

commit fd58e2eda9aa1e293905424ab27d2e6206e7ecfd
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:10:50 2026 -0500

    Add patch to fix typo in gfm var

commit 934422d503bd1d488c8a7a5b38a7689d65e6f626
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:08:30 2026 -0500

    add NotoSansSunuwar font

commit 73823d4e758d85711b167adcfe4b5d736b2812bd
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:34:08 2026 -0500

    Add libcmark-gfm-dev, libcmark-gfm-extensions-dev in B-D

commit bf2327ba04ddfa9e2fa9c3f9db6f99a976ecee5e
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:30:10 2026 -0500

    Enable OCR support

commit ccad84c37d2e586ab4ad3d107ff5e4246a1f397b
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:29:27 2026 -0500

    update series file

commit 5c03c9753d2eac829e41c0e5c0793e4c6d475ebb
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:28:58 2026 -0500

    Refresh patches

commit b5132909d09dccb7ebf5f7a6b0e45c5a3876e59d
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:27:04 2026 -0500

    Remove patches, merge with upstream

commit 402f05ee1a4c0bc6caff4578238a866eb6945866
Merge: a11c1ee a6ca022
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:22:23 2026 -0500

    Update upstream source from tag 'upstream/1.28.0+ds1'
    
    Update to upstream version '1.28.0+ds1'
    with Debian dir c27664371995080904d8f0c2c3ccbcaf44fdc07f

commit a6ca02298e9af6cf2f78010d39cf439264d8343f
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:21:55 2026 -0500

    New upstream version 1.28.0+ds1

commit a11c1eed6725a053a9333b5bf7c5a1e2d029973b
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:20:37 2026 -0500

    Exclude bundled thirdparty/cmark-gfm, we use system lib instead

commit 6786ac8c0cab4d8ce4822b51b3c2e13d832e3230
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Tue Dec 16 20:50:03 2025 -0500

    New upstream version 1.27.0+ds1

commit 0c9f8e9d25e8e007958ad0bf5f0589072043d703
Merge: 4f4bb09 474ed32
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Mon Dec 16 20:05:30 2024 +0000

    Merge branch 'upstream' into 'upstream'
    
    New upstream version 1.25.1+ds1
    
    See merge request debian/mupdf!10

commit 474ed32154a4b871dc74ff30874a228f3bc66131
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Dec 7 15:21:17 2024 -0500

    New upstream version 1.25.1+ds1

commit 4f4bb0900023531ab303d3962ee3b26057dd1a79
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Oct 5 20:02:14 2024 -0500

    New upstream version 1.24.10+ds1

commit 135fa3eb0bbc3506bc4d689c0601b27902a31ffa
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sun Sep 22 00:33:57 2024 -0500

    New upstream version 1.24.9+ds1

commit cdbddc38e19460152643bb59e5ae96931b742c2c
Author: Kan-Ru Chen <koster@debian.org>
Date:   Fri Aug 23 08:20:56 2024 +0900

    New upstream version 1.24.8+ds2

commit 94a8eb1c8541f5e9ba7f8dfbbfcfe567b9725c3c
Merge: d1b2f9c c5d84dc
Author: Kan-Ru Chen <koster@debian.org>
Date:   Thu Aug 22 08:50:26 2024 +0900

    Merge remote-tracking branch 'origin/upstream' into upstream

commit d1b2f9cecbe548a90ca371aea31eca2a076b1f07
Author: Kan-Ru Chen <koster@debian.org>
Date:   Thu Aug 22 08:10:32 2024 +0900

    New upstream version 1.24.8+ds1

commit 787e05d355770fd9a1d17417c0314128c23ca40f
Author: Kan-Ru Chen <koster@debian.org>
Date:   Sun Jun 16 07:28:01 2024 +0900

    New upstream version 1.24.3+ds1

commit 131026fdbdc12a2c6c24f4acb4962aba4e8577f4
Author: Kan-Ru Chen <koster@debian.org>
Date:   Mon Feb 12 08:16:35 2024 +0900

    New upstream version 1.23.10+ds1

commit ec03b2f8325cd2fa7dde404cbc7185edc5dc8c49
Author: Kan-Ru Chen <koster@debian.org>
Date:   Fri Jan 19 17:15:37 2024 +0900

    New upstream version 1.23.9+ds1

commit c5d84dc5acf55a4e5636c96240e571e865e1daa0
Author: Bastian Germann <bage@debian.org>
Date:   Mon Dec 4 12:10:14 2023 +0100

    New upstream version 1.23.7+ds1

commit 4cf1600e23f91b0e9d6554c3acd8c2526147db88
Author: Kan-Ru Chen <koster@debian.org>
Date:   Sat Nov 18 17:13:04 2023 +0900

    New upstream version 1.23.6+ds1

commit 61590fafcd3dfd2429b9685c9dc9a159e53f191e
Author: Kan-Ru Chen <koster@debian.org>
Date:   Sun Jul 9 07:17:49 2023 +0900

    New upstream version 1.22.2+ds1

commit cb51d8d37f4d15c1efcb1c09844d06897cc2c987
Author: Bastian Germann <bage@debian.org>
Date:   Tue Jun 13 11:34:41 2023 +0200

    New upstream version 1.22.1+ds1

commit bf80766006be6be08d08922887893c8cbb47d6c1
Author: Bastian Germann <bage@debian.org>
Date:   Wed Jan 25 01:38:04 2023 +0100

    New upstream version 1.21.1+ds2

commit ec6912351e94fecf7b05c64d483e78c71d212570
Author: Bastian Germann <bage@debian.org>
Date:   Thu Dec 15 21:00:25 2022 +0100

    New upstream version 1.21.1+ds1

commit 90f30dc9be9e4b3d7672e7e2db7025f6bc603236
Author: Bastian Germann <bage@debian.org>
Date:   Tue Nov 8 20:42:30 2022 +0100

    New upstream version 1.21.0+ds1

commit 53213302d40b3a9fa5189c90b370d4daecc2f610
Author: Bastian Germann <bage@linutronix.de>
Date:   Mon Aug 15 23:06:17 2022 +0200

    New upstream version 1.20.3+ds1

commit c872d0a464727e952b06e7ac07b038b33f4f4dd3
Author: Bastian Germann <bage@debian.org>
Date:   Sat Jun 18 21:30:04 2022 +0200

    New upstream version 1.20.0+ds1

commit 9aea2d91c5a69d2b4f22063f3f48b5ff2186b231
Author: Bastian Germann <bage@debian.org>
Date:   Tue Oct 26 11:03:15 2021 +0200

    New upstream version 1.19.0+ds1

commit bb8913fa617c6521265de35794fd45808bdcb8f1
Author: Kan-Ru Chen <kanru@kanru.info>
Date:   Sun Oct 28 12:23:29 2018 +0900

    New upstream version 1.14.0+ds1

commit 07e7958933d083e09b39ba78ddc7e559fd071a4b
Author: Kan-Ru Chen <kanru@kanru.info>
Date:   Mon Apr 30 08:52:40 2018 +0900

    New upstream version 1.13.0+ds1

commit 0fdbf3bcb0d169d0f47818bf3ce5203cca0cc093
Author: Kan-Ru Chen <kanru@kanru.info>
Date:   Wed Mar 14 09:11:21 2018 +0900

    New upstream version 1.12.0+ds1

commit 4844d430cdd649d11f6f762c4f6e25812202610e
Author: Kan-Ru Chen <koster@debian.org>
Date:   Sun Sep 24 13:06:06 2017 +0800

    New upstream version 1.11+ds1

commit 9e9fed46f6065c97ba93e5f058939e8d92e355df
Author: Kan-Ru Chen (陳侃如) <koster@debian.org>
Date:   Wed Jul 6 23:01:58 2016 +0800

    Imported Upstream version 1.9a+ds1

commit 4adcddcf13b19f46a493282d5e1f5493a47ef363
Author: Kan-Ru Chen <koster@debian.org>
Date:   Fri Sep 18 22:18:55 2015 +0800

    Imported Upstream version 1.7a

commit de7d18229a56d1de95a5dc5b7083850c546cb46a
Author: Kan-Ru Chen (陳侃如) <koster@debian.org>
Date:   Wed May 6 22:36:44 2015 +0800

    Imported Upstream version 1.7

commit 4e13fee2b04c15f9cb9610369bc9558c46de7b81
Author: Kan-Ru Chen (陳侃如) <koster@debian.org>
Date:   Sat Nov 1 19:10:22 2014 +0800

    Imported Upstream version 1.6

commit cb931ac6ace959a1b6b38d4b866ddd2d1320dc2a
Author: Kan-Ru Chen (陳侃如) <koster@debian.org>
Date:   Sat Sep 20 11:34:18 2014 +0800

    Imported Upstream version 1.5

commit b2f096de23e5341fbbcd7c290f3a144423741906
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Tue Jun 10 17:09:04 2014 +0200

    Bump version number to 1.5.

commit 14ca805423104ce90117b4b03a2de2ccfd9c277d
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Mon Jun 9 15:57:02 2014 +0200

    Fix library/header version error message and makefile dependency.

commit fdea617e38c4d4579b4edcc9ffaf7e4a8b067d6f
Author: Robin Watts <robin.watts@artifex.com>
Date:   Mon Jun 9 17:51:34 2014 +0100

    Bug 695300: Sanitize draw-device stack handling in error cases.
    
    When throwing an error during fz_alpha_from_gray, the stack depth
    can get confused. Fix this by moving some more code into the
    appropriate fz_try().
    
    In the course of fixing this bug, I added some new optional debug
    code to display the stack level as it runs. This is committed here
    disabled; just change the appropriate #define in draw-device.c to
    enable it.
    
    Also, add some code to run_xobject, to avoid throwing in an fz_always()
    clause.

commit a6f0d56d2d2e66cef2b4ca6e810bf3630ed53d0b
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Mon Jun 9 14:02:16 2014 +0200

    Fix 695300: don't throw exception on invalid reference number.
    
    Return the null object rather than throwing an exception when parsing
    indirect object references with negative object numbers.
    
    Do range check for object numbers (1 .. length) when object numbers
    are used instead.
    
    Object number 0 is not a valid object number. It must always be 'free'.

commit 0f0653cac62c7dbcd4b4cd2ea57640769271365c
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Thu May 29 15:17:47 2014 +0200

    Fix 694093: add vertical variant of CJK fallback font.
    
    Replace the DroidSansFallback TTF files with a TTC that has two fonts:
    The original and a copy where the OpenType 'vert' substitution
    lookup has been pre-applied by copying the uniXXXX.vert glyph data
    to uniXXXX.

commit 803294993c0ec927678f80ffb317770a8785f83b
Author: Simon Bünzli <zeniko@gmail.com>
Date:   Thu May 29 02:47:42 2014 +0200

    fix memory leaks during PDF document creation
    
    pdf_create_document leaks the trailer and in pdf-device.c many objects
    are inserted into dictionaries using pdf_dict_puts and leaked instead
    of using pdf_dict_puts_drop.

commit 68b6b1ea0ec475bcf1fe706dd4ed06b96ebe9f28
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Wed May 28 14:29:44 2014 +0200

    Tolerate zero-sized xref sections...
    
    ...like the one Microsoft Word generates.

commit e7bd6babd4b6567db153806eb928591f2b26f4e2
Author: Robin Watts <robin.watts@artifex.com>
Date:   Tue May 27 18:11:07 2014 +0100

    Further fix for Bug 695260: Cope with out of memory in fz_draw_end_mask
    
    If we hit an out of memory error in fz_draw_end_mask, then pop the
    stack, and rethrow. Ensure that the generic device code catches this
    error and sets the error_depth to 1 so that the final pop is ignored.

commit 165975f819d6aa44c9d22576b3d913c86b90fa11
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Wed May 28 13:58:45 2014 +0200

    Save a bookmark before jumping when using the 'g' command.

commit 295b1edf02754e668831773769a270c12441cd5d
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Tue May 27 17:13:57 2014 +0200

    Fix 693517: Support /SMask/Matte preblended images.

commit 2f1f3840295b8152d44d00a3c14b58a737baefa7
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Tue May 27 14:48:28 2014 +0200

    Fix 693494: Support media buttons for navigation on X11.

commit c357c281a6dde7ec9a2d265237a2790a7e1ed306
Author: Sebastian Neuser <haggl@sineband.de>
Date:   Wed Aug 14 00:39:05 2013 +0200

    Fix 694518: Implement continuous scrolling with keyboard.

commit a65d4da6b8073a67c69f3c716152a7072770db40
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Tue May 27 14:16:09 2014 +0200

    Set a faster default transition.

commit 955b7137fa4982b596ce0acf2fb7b9a497376320
Author: Sebastian Neuser <haggl@sineband.de>
Date:   Thu Aug 15 20:04:23 2013 +0200

    Fix 694579: Implement "zoom to fit page".
    
    Add a new function pdfapp_autozoom to fit the page to the window by comparing
    the aspect ratios of the page and the window to choose whether to fit
    horizontally or vertically.

commit 0c041d7fc030a9bb25c76ad72a9a028e32a78de1
Author: Robin Watts <robin.watts@artifex.com>
Date:   Mon May 26 17:34:14 2014 +0100

    Bug 695260: Fix error handling in do_xobject
    
    Various functions (such as fz_begin_group) handle errors internally
    by use of the error_depth parameter. This means that if we call
    them, we MUST ensure that we call the appropriate closing function.
    Similarly, if we don't call them, we should NOT call the closing
    function.
    
    In order to ensure we do this correctly, we introduce a cleanup_state
    variable that says which ones we tried to call.
    
    This cures the original bug.

commit 253a976aa4c0993c0b685deaceefb3220a0825d1
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Mon May 26 16:56:34 2014 +0200

    Fix 695261: separate TM and CTM in outline extraction and stroking steps.
    
    We used to extract the outline using the combined TM*CTM matrix and
    use the identity transform for stroking, thus ending up with the wrong
    line width.
    
    If we instead extract using the TM and then stroke with the CTM we get
    the correct results.

commit 5aa2e01f585075cea6854897503f72fcb6f6a8a0
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Fri May 23 15:13:39 2014 +0200

    Fix 695041: add special fast case for 8bpp TIFF predictor.

commit 30dcebf32f5ac4df97ef477c6a5b4a8c8d247527
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Thu May 22 22:17:20 2014 +0200

    Add ftdebug.c to thirdparty freetype build.
    
    Allows compilation with -DFT_DEBUG_LEVEL_TRACE to track down buggy fonts.

commit 074cd54f24d7b2121c3873e3b62a2161b2e014e0
Author: Robin Watts <robin.watts@artifex.com>
Date:   Fri May 23 11:46:04 2014 +0100

    Bug 695183: Inflate large buffers at a time for speed.
    
    When I changed the stream implementations to use implementation
    specific buffers, rather than a generic public one in every fz_stream,
    I changed fz_read_byte to only get a single byte at a time.
    
    I noted at the time that the underlying stream was free to decode
    larger blocks if it wanted too, but I forgot to actually do this for
    the flate decoder. Fixing this here should solve the speed issues.

commit 3eba9a357d65f9dfd4854b6645e09015e2e0267c
Author: Robin Watts <robin.watts@artifex.com>
Date:   Thu May 22 19:41:56 2014 +0100

    Flush pending text on a change of CTM.
    
    Without this, comparefiles/Bug695086 renders the barcode test upside
    down.

commit 20bbb37a9b3403d5b7542e47adf88408c71bbac9
Author: Robin Watts <robin.watts@artifex.com>
Date:   Thu May 22 17:22:55 2014 +0100

    Fix windows VS builds.
    
    Fix broken solution file and add project entries for new files.

commit 5bbe8607b4eff874efd85e357450c46a6f7c7593
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Thu May 22 15:47:56 2014 +0200

    Fix 695222: Treat non-breaking space (U+00A0) as white space for search.

commit 3c4bd6130b6e2ff423e38654e0dcc8502f22274a
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Thu May 22 14:03:24 2014 +0200

    Fix 695247: Use exponential realloc pattern and qsort for huge paths.
    
    Grow the edge list using an exponential realloc pattern.
    Use qsort for huge paths and only fall back to the simple
    shell sort for small paths.

commit 2191d24236c6e2283521a4013dbca2b4feb6c6e7
Author: Tor Andersson <tor.andersson@artifex.com>
Date:   Thu May 22 12:54:50 2014 +0200

    Load the usecmap directives recursively for builtin CMaps.
    
    Fixes bug introduced in commit 1679c1e7a89ae62260fd84ce55c6bef376c6e6ba:
    
        Optimize UniXXX CMap files.


https://salsa.debian.org/api/v4/projects/debian%2Fmupdf API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-07-24 Last update: 2026-07-31 05:31
6 low-priority security issues in trixie low

There are 6 open security issues in trixie.

6 issues left for the package maintainer to handle:
  • CVE-2026-7233: (needs triaging) A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
  • CVE-2025-46206: (needs triaging) An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion
  • CVE-2025-55780: (needs triaging) A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.
  • CVE-2025-71382: (needs triaging) MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in css-apply.c recurses through the CSS property inheritance chain without a depth limit, exhausting the process stack and causing a crash in any application using MuPDF for EPUB rendering.
  • CVE-2026-25556: (needs triaging) MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception. Callers (including the barcode decoding path in fz_decode_barcode_from_display_list) also drop the same pixmap in cleanup, resulting in a double-free that can corrupt the heap and crash the process. This issue affects applications that enable and use MuPDF barcode decoding and can be triggered by processing crafted input that causes a rendering-time error while decoding barcodes.
  • CVE-2026-40505: (needs triaging) MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.

You can find information about how to handle these issues in the security team's documentation.

Created: 2025-08-09 Last update: 2026-07-26 01:20
5 low-priority security issues in bookworm low

There are 5 open security issues in bookworm.

5 issues left for the package maintainer to handle:
  • CVE-2026-7233: (needs triaging) A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
  • CVE-2025-46206: (needs triaging) An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion
  • CVE-2025-55780: (needs triaging) A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.
  • CVE-2025-71382: (postponed; to be fixed through a stable update) MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in css-apply.c recurses through the CSS property inheritance chain without a depth limit, exhausting the process stack and causing a crash in any application using MuPDF for EPUB rendering.
  • CVE-2026-40505: (needs triaging) MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.

You can find information about how to handle these issues in the security team's documentation.

Created: 2025-08-04 Last update: 2026-07-26 01:20
debian/patches: 12 patches to forward upstream low

Among the 19 debian patches available in version 1.27.0+ds1-6 of the package, we noticed the following issues:

  • 12 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-05-17 15:04
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-05-26] mupdf 1.27.0+ds1-6 MIGRATED to testing (Debian testing watch)
  • [2026-05-17] Accepted mupdf 1.27.0+ds1-6 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-04-25] Accepted mupdf 1.21.1+ds2-1+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-25] mupdf 1.27.0+ds1-5 MIGRATED to testing (Debian testing watch)
  • [2026-04-20] Accepted mupdf 1.17.0+ds1-2+deb11u2 (source) into oldoldstable-security (Emilio Pozuelo Monfort)
  • [2026-04-20] Accepted mupdf 1.27.0+ds1-5 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-04-19] Accepted mupdf 1.25.1+ds1-6+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-18] Accepted mupdf 1.25.1+ds1-6+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-18] Accepted mupdf 1.21.1+ds2-1+deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-17] mupdf 1.27.0+ds1-4 MIGRATED to testing (Debian testing watch)
  • [2026-04-12] Accepted mupdf 1.27.0+ds1-4 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-02-13] mupdf 1.27.0+ds1-3 MIGRATED to testing (Debian testing watch)
  • [2026-02-08] Accepted mupdf 1.27.0+ds1-3 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-01-24] mupdf 1.27.0+ds1-2 MIGRATED to testing (Debian testing watch)
  • [2026-01-18] Accepted mupdf 1.27.0+ds1-2 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-01-08] Accepted mupdf 1.27.0+ds1-1 (source amd64) into experimental (Debian FTP Masters) (signed by: Daniel Echeverry)
  • [2025-10-26] Accepted mupdf 1.25.1+ds1-9 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-10-25] Accepted mupdf 1.25.1+ds1-8 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-09-23] mupdf 1.25.1+ds1-7 MIGRATED to testing (Debian testing watch)
  • [2025-08-22] Accepted mupdf 1.17.0+ds1-2+deb11u1 (source) into oldoldstable-security (Chris Lamb)
  • [2025-08-07] Accepted mupdf 1.25.1+ds1-7 (source) into unstable (Kan-Ru Chen (陳侃如)) (signed by: Kan-Ru Chen)
  • [2025-05-02] mupdf 1.25.1+ds1-6 MIGRATED to testing (Debian testing watch)
  • [2025-04-22] Accepted mupdf 1.25.1+ds1-6 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-02-14] mupdf 1.25.1+ds1-5 MIGRATED to testing (Debian testing watch)
  • [2025-01-11] Accepted mupdf 1.25.1+ds1-5 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-01-07] Accepted mupdf 1.25.1+ds1-4 (source amd64) into experimental (Debian FTP Masters) (signed by: Daniel Echeverry)
  • [2025-01-02] Accepted mupdf 1.25.1+ds1-3 (source) into experimental (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2024-12-31] Accepted mupdf 1.25.1+ds1-2 (source) into experimental (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2024-12-21] Accepted mupdf 1.25.1+ds1-1 (source amd64) into experimental (Debian FTP Masters) (signed by: Daniel Echeverry)
  • [2024-10-16] mupdf 1.24.10+ds1-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 27
  • RC: 0
  • I&N: 20
  • M&W: 7
  • F&P: 0
  • patch: 3
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.27.0+ds1-3ubuntu2
  • patches for 1.27.0+ds1-3ubuntu2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing