CVE-2025-50422

Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.
Configurations

No configuration.

History

10 Aug 2025, 02:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 2.9
Summary (en) An issue was discovered in freedesktop poppler v25.04.0. The heap memory containing PDF stream objects is not cleared upon program exit, allowing attackers to obtain sensitive PDF content via a memory dump. (en) Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.
CWE CWE-617
References
  • {'url': 'http://freedesktop.com', 'source': 'cve@mitre.org'}
  • {'url': 'http://poppler.com', 'source': 'cve@mitre.org'}
  • () https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/621 -
  • () https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591 -
  • () https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591#note_3045081 -

05 Aug 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.5

05 Aug 2025, 14:34

Type Values Removed Values Added
Summary
  • (es) Se detectó un problema en freedesktop poppler v25.04.0. La memoria del montón que contiene los objetos de flujo PDF no se borra al salir del programa, lo que permite a los atacantes obtener contenido PDF confidencial mediante un volcado de memoria.

04 Aug 2025, 20:15

Type Values Removed Values Added
CWE CWE-244
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

04 Aug 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-04 17:15

Updated : 2025-08-10 02:15


NVD link : CVE-2025-50422

Mitre link : CVE-2025-50422

CVE.ORG link : CVE-2025-50422


JSON object : View

Products Affected

No product.

CWE
CWE-617

Reachable Assertion

CWE-244

Improper Clearing of Heap Memory Before Release ('Heap Inspection')