CVE-2026-3308
An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap out-of-bounds write that could be exploited for arbitrary code execution.
References
Affected products
- =<1.27.0
Matching in nixpkgs
pkgs.mupdf
Lightweight PDF, XPS, and E-book viewer and toolkit written in portable C
pkgs.mupdf-headless
Lightweight PDF, XPS, and E-book viewer and toolkit written in portable C
pkgs.python312Packages.pymupdf
Python bindings for MuPDF's rendering library
pkgs.python313Packages.pymupdf
Python bindings for MuPDF's rendering library
pkgs.python314Packages.pymupdf
Python bindings for MuPDF's rendering library
pkgs.python312Packages.pymupdf4llm
PyMuPDF Utilities for LLM/RAG - converts PDF pages to Markdown format for Retrieval-Augmented Generation
-
nixos-25.11 pymupdf4llm-0.0.27
- nixos-25.11-small pymupdf4llm-0.0.27
- nixpkgs-25.11-darwin pymupdf4llm-0.0.27
pkgs.python313Packages.pymupdf4llm
PyMuPDF Utilities for LLM/RAG - converts PDF pages to Markdown format for Retrieval-Augmented Generation
-
nixos-unstable pymupdf4llm-0.3.4
- nixpkgs-unstable pymupdf4llm-0.3.4
- nixos-unstable-small pymupdf4llm-0.3.4
-
nixos-25.11 pymupdf4llm-0.0.27
- nixos-25.11-small pymupdf4llm-0.0.27
- nixpkgs-25.11-darwin pymupdf4llm-0.0.27
pkgs.python314Packages.pymupdf4llm
PyMuPDF Utilities for LLM/RAG - converts PDF pages to Markdown format for Retrieval-Augmented Generation
-
nixos-unstable pymupdf4llm-0.3.4
- nixpkgs-unstable pymupdf4llm-0.3.4
- nixos-unstable-small pymupdf4llm-0.3.4
pkgs.zathuraPkgs.zathura_pdf_mupdf
Zathura PDF plugin (mupdf)
-
nixos-unstable 2026.02.03
- nixpkgs-unstable 2026.02.03
- nixos-unstable-small 2026.02.03
pkgs.python312Packages.pymupdf-fonts
Collection of optional fonts for PyMuPDF
pkgs.python313Packages.pymupdf-fonts
Collection of optional fonts for PyMuPDF
pkgs.python314Packages.pymupdf-fonts
Collection of optional fonts for PyMuPDF
Package maintainers
-
@fpletz Franz Pletz <fpletz@fnordicwalking.de>
-
@ryota2357 Ryota Otsuki <contact@ryota2357.com>
-
@sarahec Sarah Clark <seclark@nextquestion.net>