View Issue Details

IDProjectCategoryView StatusLast Update
0011584Rocky-Linux-8ghostscriptpublic2026-01-03 00:17
ReporterBrad Thompson Assigned To 
PriorityhighSeveritymajorReproducibilityhave not tried
Status newResolutionopen 
PlatformLinuxOSRocky LinuxOS Version8.10
Summary0011584: Ghostscript 9.27-17.el8_10 horribly outdated and multiple CVE Vulnerabilities
DescriptionGhostScript needs to be upgraded to version 10.05.0 or above.

All NVD Base Score 9.8

CVE-2025-27837
CVE-2025-27831
CVE-2025-27836
CVE-2025-27837
CVE-2025-27831
CVE-2025-27836
Steps To ReproduceAlerts produced by Sentinel One.
Additional InformationTemporary hardening is possible.

# Disable PostScript/PDF processing in ImageMagick policy (if not needed)
sudo nano /etc/ImageMagick-6/policy.xml

Add these lines before </policymap> to block Ghostscript delegates:

<policy domain="coder" rights="none" pattern="PS" />
<policy domain="coder" rights="none" pattern="EPS" />
<policy domain="coder" rights="none" pattern="PDF" />

This prevents ImageMagick from processing PDF/PostScript files entirely, eliminating the Ghostscript attack vector while keeping imagick functional for image formats. Only implement this if your hosted sites don't need PDF manipulation through ImageMagick.
TagsNo tags attached.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2026-01-03 00:17 Brad Thompson New Issue