Debian Package Tracker
Register | Log in
Subscribe

mupdf

lightweight PDF viewer

Choose email to subscribe with

general
  • source: mupdf (main)
  • version: 1.27.0+ds1-6
  • maintainer: Kan-Ru Chen (陳侃如) (DMD)
  • uploaders: Daniel Echeverri [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.17.0+ds1-2
  • o-o-sec: 1.17.0+ds1-2+deb11u2
  • oldstable: 1.21.1+ds2-1+deb12u1
  • old-sec: 1.21.1+ds2-1+deb12u1
  • stable: 1.25.1+ds1-6+deb13u1
  • stable-sec: 1.25.1+ds1-6+deb13u1
  • testing: 1.27.0+ds1-6
  • unstable: 1.27.0+ds1-6
  • exp: 1.28.0+ds1-1
versioned links
  • 1.17.0+ds1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.17.0+ds1-2+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.21.1+ds2-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.25.1+ds1-6+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.27.0+ds1-6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.28.0+ds1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libmupdf-dev
  • libmupdf27.0
  • mupdf (21 bugs: 0, 15, 6, 0)
  • mupdf-tools (2 bugs: 0, 2, 0, 0)
  • python3-mupdf
action needed
A new upstream version is available: 1.28.2 high
A new upstream version 1.28.2 is available, you should consider packaging it.
Created: 2026-05-18 Last update: 2026-08-24 03:03
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-7233: A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Created: 2026-04-28 Last update: 2026-08-02 20:32
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-7233: A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Created: 2026-04-28 Last update: 2026-08-02 20:32
3 bugs tagged patch in the BTS normal
The BTS contains patches fixing 3 bugs, consider including or untagging them.
Created: 2026-08-15 Last update: 2026-08-24 06:18
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 1.28.2+ds1-1, distribution experimental) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit 735dfebc7744ed57cca6d4b9a278db1ed9b2e9fa
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sun Aug 23 21:25:27 2026 -0500

    Prepare Debian version 1.28.2+ds1-1

commit f62d195254e015470ef8ed3bee43c0a20f770ae5
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sun Aug 23 19:42:04 2026 -0500

    Refresh patches

commit 1d0d36595cccac4081b6fe4009560e9680c0e623
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sun Aug 23 19:41:24 2026 -0500

    Add STRIP_FROM_PATH to avoid embedding the build path in doc

commit bb7c22185d08371e3ec85310990fbf7419e9f80e
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Aug 22 16:32:57 2026 -0500

    fix Breaks/Replaces version

commit 80de98bdef256198c902c3b69b34823acda6127e
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Aug 22 14:07:39 2026 -0500

    Prepare Debian version 1.28.2+ds1-1

commit b18ee80f416710156d5a213973cf5d44c01ffd0b
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Aug 22 14:05:29 2026 -0500

    Add Breaks/Replaces against libmupdf28.0

commit 2ed5803d623e49c001f24a6c04cfc132ba558062
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Aug 22 12:53:14 2026 -0500

    Prepare Debian version 1.28.2+ds1-1

commit e2801bf50e304ed006361040ce68e319334657bd
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Aug 22 12:51:59 2026 -0500

    Fix Charis SIL font symlinks after upstream rename in 7.000

commit 35eed94e5c200767fa19aeca882e7421eecda622
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Aug 22 10:33:38 2026 -0500

    Update symbols file

commit 96a92e31ab3d8f72974af7560c28deff22e2a67e
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Aug 22 10:32:18 2026 -0500

    Add python3-pipcl in B-D

commit dc76dee31518d112ae1b4c89200cbd7872545400
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Aug 22 10:28:36 2026 -0500

    Rename lib package to libmupdf28.2 for new soname

commit aa36e28044d194016dd4ff50d7fe8a5f36ce9a77
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Aug 22 10:25:19 2026 -0500

    Add patch to fix build with swig 4.5

commit 66839f0dfb71a1b54f496d2955f5c08c0a8b2977
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Aug 22 10:22:27 2026 -0500

    Rename file

commit b5e5373a9033c4b93821c26185d919835d6eb65a
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Sat Aug 22 10:21:33 2026 -0500

    Update patch to disable venv by default

commit b5d01d41512a2786de7c38739d63e6902beaebbc
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Mon Aug 17 14:22:18 2026 -0500

    Refresh patch

commit e4be02581031d06aa1074e0363e82b6b34b901c9
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Mon Aug 17 14:22:07 2026 -0500

    Refresh patch

commit 6001a7a30a61ed30088005d8894e570ce3e21b80
Merge: 022e6df 7711a69
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Mon Aug 17 14:14:13 2026 -0500

    Update upstream source from tag 'upstream/1.28.2+ds1'
    
    Update to upstream version '1.28.2+ds1'
    with Debian dir 9a15e0a1c5f437c8334b71653e4eb9c97f6c3f62

commit 7711a697d51bfc9e8a9c5a3842f3dd61272b8aaf
Author: Daniel Echeverri <epsilon@debian.org>
Date:   Mon Aug 17 14:13:41 2026 -0500

    New upstream version 1.28.2+ds1


https://salsa.debian.org/api/v4/projects/debian%2Fmupdf API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-08-22 Last update: 2026-08-24 04:32
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • libmupdf27.0 could be marked Multi-Arch: same
Created: 2026-05-18 Last update: 2026-08-24 00:30
6 low-priority security issues in trixie low

There are 6 open security issues in trixie.

6 issues left for the package maintainer to handle:
  • CVE-2026-7233: (needs triaging) A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
  • CVE-2025-46206: (needs triaging) An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion
  • CVE-2025-55780: (needs triaging) A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.
  • CVE-2025-71382: (needs triaging) MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in css-apply.c recurses through the CSS property inheritance chain without a depth limit, exhausting the process stack and causing a crash in any application using MuPDF for EPUB rendering.
  • CVE-2026-25556: (needs triaging) MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception. Callers (including the barcode decoding path in fz_decode_barcode_from_display_list) also drop the same pixmap in cleanup, resulting in a double-free that can corrupt the heap and crash the process. This issue affects applications that enable and use MuPDF barcode decoding and can be triggered by processing crafted input that causes a rendering-time error while decoding barcodes.
  • CVE-2026-40505: (needs triaging) MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.

You can find information about how to handle these issues in the security team's documentation.

Created: 2025-08-09 Last update: 2026-08-02 20:32
debian/patches: 12 patches to forward upstream low

Among the 19 debian patches available in version 1.27.0+ds1-6 of the package, we noticed the following issues:

  • 12 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-05-17 15:04
testing migrations
  • This package will soon be part of the auto-mupdf transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-08-24] Accepted mupdf 1.28.2+ds1-1 (source amd64 all) into experimental (Debian FTP Masters) (signed by: Daniel Echeverri)
  • [2026-08-06] Accepted mupdf 1.28.0+ds1-1 (source amd64 all) into experimental (Debian FTP Masters) (signed by: Daniel Echeverri)
  • [2026-05-26] mupdf 1.27.0+ds1-6 MIGRATED to testing (Debian testing watch)
  • [2026-05-17] Accepted mupdf 1.27.0+ds1-6 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-04-25] Accepted mupdf 1.21.1+ds2-1+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-25] mupdf 1.27.0+ds1-5 MIGRATED to testing (Debian testing watch)
  • [2026-04-20] Accepted mupdf 1.17.0+ds1-2+deb11u2 (source) into oldoldstable-security (Emilio Pozuelo Monfort)
  • [2026-04-20] Accepted mupdf 1.27.0+ds1-5 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-04-19] Accepted mupdf 1.25.1+ds1-6+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-18] Accepted mupdf 1.25.1+ds1-6+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-18] Accepted mupdf 1.21.1+ds2-1+deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-17] mupdf 1.27.0+ds1-4 MIGRATED to testing (Debian testing watch)
  • [2026-04-12] Accepted mupdf 1.27.0+ds1-4 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-02-13] mupdf 1.27.0+ds1-3 MIGRATED to testing (Debian testing watch)
  • [2026-02-08] Accepted mupdf 1.27.0+ds1-3 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-01-24] mupdf 1.27.0+ds1-2 MIGRATED to testing (Debian testing watch)
  • [2026-01-18] Accepted mupdf 1.27.0+ds1-2 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2026-01-08] Accepted mupdf 1.27.0+ds1-1 (source amd64) into experimental (Debian FTP Masters) (signed by: Daniel Echeverry)
  • [2025-10-26] Accepted mupdf 1.25.1+ds1-9 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-10-25] Accepted mupdf 1.25.1+ds1-8 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-09-23] mupdf 1.25.1+ds1-7 MIGRATED to testing (Debian testing watch)
  • [2025-08-22] Accepted mupdf 1.17.0+ds1-2+deb11u1 (source) into oldoldstable-security (Chris Lamb)
  • [2025-08-07] Accepted mupdf 1.25.1+ds1-7 (source) into unstable (Kan-Ru Chen (陳侃如)) (signed by: Kan-Ru Chen)
  • [2025-05-02] mupdf 1.25.1+ds1-6 MIGRATED to testing (Debian testing watch)
  • [2025-04-22] Accepted mupdf 1.25.1+ds1-6 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-02-14] mupdf 1.25.1+ds1-5 MIGRATED to testing (Debian testing watch)
  • [2025-01-11] Accepted mupdf 1.25.1+ds1-5 (source) into unstable (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2025-01-07] Accepted mupdf 1.25.1+ds1-4 (source amd64) into experimental (Debian FTP Masters) (signed by: Daniel Echeverry)
  • [2025-01-02] Accepted mupdf 1.25.1+ds1-3 (source) into experimental (Daniel Echeverri) (signed by: Daniel Echeverry)
  • [2024-12-31] Accepted mupdf 1.25.1+ds1-2 (source) into experimental (Daniel Echeverri) (signed by: Daniel Echeverry)
  • 1
  • 2
bugs [bug history graph]
  • all: 26
  • RC: 1
  • I&N: 19
  • M&W: 6
  • F&P: 0
  • patch: 3
links
  • homepage
  • lintian
  • buildd: logs, exp, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.27.0+ds1-3ubuntu3
  • patches for 1.27.0+ds1-3ubuntu3

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing