Debian Package Tracker
Register | Log in
Subscribe

mupdf

lightweight PDF viewer

Choose email to subscribe with

general
  • source: mupdf (main)
  • version: 1.27.0+ds1-6
  • maintainer: Kan-Ru Chen (陳侃如) (DMD)
  • uploaders: Daniel Echeverri [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.17.0+ds1-2
  • o-o-sec: 1.17.0+ds1-2+deb11u2
  • oldstable: 1.21.1+ds2-1+deb12u1
  • old-sec: 1.21.1+ds2-1+deb12u1
  • stable: 1.25.1+ds1-6+deb13u1
  • stable-sec: 1.25.1+ds1-6+deb13u1
  • testing: 1.27.0+ds1-6
  • unstable: 1.27.0+ds1-6
  • exp: 1.28.0+ds1-1
versioned links
  • 1.17.0+ds1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.17.0+ds1-2+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.21.1+ds2-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.25.1+ds1-6+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.27.0+ds1-6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.28.0+ds1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libmupdf-dev
  • libmupdf27.0
  • mupdf (21 bugs: 0, 15, 6, 0)
  • mupdf-tools (2 bugs: 0, 2, 0, 0)
  • python3-mupdf
action needed
A new upstream version is available: 1.28.2 high
A new upstream version 1.28.2 is available, you should consider packaging it.
Created: 2026-05-18 Last update: 2026-08-07 17:01
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-7233: A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Created: 2026-04-28 Last update: 2026-08-02 20:32
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-7233: A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Created: 2026-04-28 Last update: 2026-08-02 20:32
2 bugs tagged patch in the BTS normal
The BTS contains patches fixing 2 bugs, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-08-07 22:30
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • libmupdf27.0 could be marked Multi-Arch: same
Created: 2026-05-18 Last update: 2026-08-07 19:31
30 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 022e6dfa4747183bbba82f4c3438e75ffe64321a
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Fri Jul 31 22:58:13 2026 -0500

    Prepare Debian version 1.28.0+ds1-1

commit ff2e994c568ad16bcdf8e1bc51bbb88c5ccb4c99
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Fri Jul 31 22:53:37 2026 -0500

    Add patch to remove a cmark extension that isnt available in debian

commit d364ce6d57b0203cb7165f0af09d91f873ca4bf1
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Fri Jul 31 22:39:57 2026 -0500

    Rename mupdf.doc-base to mupdf-doc.doc-base

commit f306b01664024d1d93138bb54bbd82f7a47172e2
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Fri Jul 31 22:16:59 2026 -0500

    Rename mupdf.links to mupdf-doc.links

commit 80b9b9f686b2a681461e3d4245be1734fb5d5b6c
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Fri Jul 31 22:16:14 2026 -0500

    Use DEB_VERSION_UPSTREAM instead dpkg-parsechangelog and install doc in mupdf-doc package

commit e73e2c367aed80e07a277bed20eea5ea68941393
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Fri Jul 31 22:15:16 2026 -0500

    Add mupdf-doc package

commit b1c5941ab88eb2cbea86c0fc53bcee8f8132be48
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Fri Jul 31 22:13:04 2026 -0500

    Use SOURCE_DATE_EPOCH var in doc, for make it reproducible

commit c0bbf60ba91ec407688a5f199731dfce8632550c
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Fri Jul 31 22:05:00 2026 -0500

    Add new symbols

commit 6515671775ba4253dc4a3320377ecd527d7ff07f
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Fri Jul 31 22:02:43 2026 -0500

    Add missing CXXFLAGS

commit a9755b86cfecb4d2dc0a8b4c1eaa81654fa63985
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Fri Jul 31 21:43:24 2026 -0500

    fix typo

commit 30595cd0fc575ff4fc0d6ab24dd0cffdd1f8f379
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:53:21 2026 -0500

    Update changelog file

commit 385269cf4918468024e4625d9dd3ed9711ae2a41
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:41:24 2026 -0500

    Add flags to use system cmark-gfm library

commit 7a72021bbbcd5cb98d68f4fb2086cd424c10e748
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:39:37 2026 -0500

    Add doxygen in B-D

commit f42750c47bcec398f0defca3ce3270cc39ef6c08
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:38:02 2026 -0500

    Rename lib package to libmupdf28.0 for new soname

commit 77562e93dfa04096efd44a80c1cc54a26a4f5553
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:36:09 2026 -0500

    Install mupdf-x11-curl binary

commit 7fb182e469227507469d98e3cb37318a4fbcb2ab
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:35:28 2026 -0500

    Update clean file

commit c1d60a65db09fe475d7a7be01bd92b84fdd28340
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:29:19 2026 -0500

    Rename libmupdf27.0.install to libmupdf28.0.install

commit 2742baf8430ed4eec40edaab9b0acddd61ab6acd
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:27:22 2026 -0500

    Add new symbols file

commit 8db9de743d3cc69714de905c667ceec2ef997222
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:26:06 2026 -0500

    Remove old symbols file

commit ea57813e744b34c06aaa640d34739d26ae652793
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:21:51 2026 -0500

    Add patch to remove venv param and dont build latex doc

commit fd58e2eda9aa1e293905424ab27d2e6206e7ecfd
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:10:50 2026 -0500

    Add patch to fix typo in gfm var

commit 934422d503bd1d488c8a7a5b38a7689d65e6f626
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Thu Jul 30 22:08:30 2026 -0500

    add NotoSansSunuwar font

commit 73823d4e758d85711b167adcfe4b5d736b2812bd
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:34:08 2026 -0500

    Add libcmark-gfm-dev, libcmark-gfm-extensions-dev in B-D

commit bf2327ba04ddfa9e2fa9c3f9db6f99a976ecee5e
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:30:10 2026 -0500

    Enable OCR support

commit ccad84c37d2e586ab4ad3d107ff5e4246a1f397b
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:29:27 2026 -0500

    update series file

commit 5c03c9753d2eac829e41c0e5c0793e4c6d475ebb
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:28:58 2026 -0500

    Refresh patches

commit b5132909d09dccb7ebf5f7a6b0e45c5a3876e59d
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:27:04 2026 -0500

    Remove patches, merge with upstream

commit 402f05ee1a4c0bc6caff4578238a866eb6945866
Merge: a11c1ee a6ca022
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:22:23 2026 -0500

    Update upstream source from tag 'upstream/1.28.0+ds1'
    
    Update to upstream version '1.28.0+ds1'
    with Debian dir c27664371995080904d8f0c2c3ccbcaf44fdc07f

commit a6ca02298e9af6cf2f78010d39cf439264d8343f
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:21:55 2026 -0500

    New upstream version 1.28.0+ds1

commit a11c1eed6725a053a9333b5bf7c5a1e2d029973b
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Wed Jul 29 20:20:37 2026 -0500

    Exclude bundled thirdparty/cmark-gfm, we use system lib instead


https://salsa.debian.org/api/v4/projects/debian%2Fmupdf API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-07-24 Last update: 2026-08-06 10:00
6 low-priority security issues in trixie low

There are 6 open security issues in trixie.

6 issues left for the package maintainer to handle:
  • CVE-2026-7233: (needs triaging) A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
  • CVE-2025-46206: (needs triaging) An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion
  • CVE-2025-55780: (needs triaging) A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.
  • CVE-2025-71382: (needs triaging) MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in css-apply.c recurses through the CSS property inheritance chain without a depth limit, exhausting the process stack and causing a crash in any application using MuPDF for EPUB rendering.
  • CVE-2026-25556: (needs triaging) MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception. Callers (including the barcode decoding path in fz_decode_barcode_from_display_list) also drop the same pixmap in cleanup, resulting in a double-free that can corrupt the heap and crash the process. This issue affects applications that enable and use MuPDF barcode decoding and can be triggered by processing crafted input that causes a rendering-time error while decoding barcodes.
  • CVE-2026-40505: (needs triaging) MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.

You can find information about how to handle these issues in the security team's documentation.

Created: 2025-08-09 Last update: 2026-08-02 20:32
debian/patches: 12 patches to forward upstream low

Among the 19 debian patches available in version 1.27.0+ds1-6 of the package, we noticed the following issues:

  • 12 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-05-17 15:04
testing migrations
  • This package will soon be part of the auto-mupdf transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-08-06] Accepted mupdf 1.28.0+ds1-1 (source amd64 all) into experimental (Debian FTP Masters) (signed by: Daniel Echeverri)
  • [2026-05-26] mupdf 1.27.0+ds1-6 MIGRATED to testing (Debian testing watch)
  • [2026-05-17] Accepted mupdf 1.27.0+ds1-6 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-04-25] Accepted mupdf 1.21.1+ds2-1+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-25] mupdf 1.27.0+ds1-5 MIGRATED to testing (Debian testing watch)
  • [2026-04-20] Accepted mupdf 1.17.0+ds1-2+deb11u2 (source) into oldoldstable-security (Emilio Pozuelo Monfort)
  • [2026-04-20] Accepted mupdf 1.27.0+ds1-5 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-04-19] Accepted mupdf 1.25.1+ds1-6+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-18] Accepted mupdf 1.25.1+ds1-6+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-18] Accepted mupdf 1.21.1+ds2-1+deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-17] mupdf 1.27.0+ds1-4 MIGRATED to testing (Debian testing watch)
  • [2026-04-12] Accepted mupdf 1.27.0+ds1-4 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-02-13] mupdf 1.27.0+ds1-3 MIGRATED to testing (Debian testing watch)
  • [2026-02-08] Accepted mupdf 1.27.0+ds1-3 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-01-24] mupdf 1.27.0+ds1-2 MIGRATED to testing (Debian testing watch)
  • [2026-01-18] Accepted mupdf 1.27.0+ds1-2 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-01-08] Accepted mupdf 1.27.0+ds1-1 (source amd64) into experimental (Debian FTP Masters) (signed by: Daniel Echeverry)
  • [2025-10-26] Accepted mupdf 1.25.1+ds1-9 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-10-25] Accepted mupdf 1.25.1+ds1-8 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-09-23] mupdf 1.25.1+ds1-7 MIGRATED to testing (Debian testing watch)
  • [2025-08-22] Accepted mupdf 1.17.0+ds1-2+deb11u1 (source) into oldoldstable-security (Chris Lamb)
  • [2025-08-07] Accepted mupdf 1.25.1+ds1-7 (source) into unstable (Kan-Ru Chen (陳侃如)) (signed by: Kan-Ru Chen)
  • [2025-05-02] mupdf 1.25.1+ds1-6 MIGRATED to testing (Debian testing watch)
  • [2025-04-22] Accepted mupdf 1.25.1+ds1-6 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-02-14] mupdf 1.25.1+ds1-5 MIGRATED to testing (Debian testing watch)
  • [2025-01-11] Accepted mupdf 1.25.1+ds1-5 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-01-07] Accepted mupdf 1.25.1+ds1-4 (source amd64) into experimental (Debian FTP Masters) (signed by: Daniel Echeverry)
  • [2025-01-02] Accepted mupdf 1.25.1+ds1-3 (source) into experimental (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2024-12-31] Accepted mupdf 1.25.1+ds1-2 (source) into experimental (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2024-12-21] Accepted mupdf 1.25.1+ds1-1 (source amd64) into experimental (Debian FTP Masters) (signed by: Daniel Echeverry)
  • 1
  • 2
bugs [bug history graph]
  • all: 25
  • RC: 0
  • I&N: 19
  • M&W: 6
  • F&P: 0
  • patch: 2
links
  • homepage
  • lintian
  • buildd: logs, exp, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.27.0+ds1-3ubuntu2
  • patches for 1.27.0+ds1-3ubuntu2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing