UBUNTU-CVE-2026-19547

Source
https://ubuntu.com/security/CVE-2026-19547
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-19547.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-19547
Upstream
  • CVE-2026-19547
Published
2026-09-29T10:17:00Z
Modified
2026-10-01T00:21:06Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\gs\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any authenticated user to create directories at the root of C:\, an attacker who is an authenticated local user can create the expected directory structure and plant a malicious PostScript file. When any user or service subsequently runs Ghostscript, the planted file is automatically loaded and executed with the full privileges of the Ghostscript process. This results in full compromise of Ghostscript process context, as well as running arbitrary code on the machine with Ghostscript process privileges. This issue was fixed in version 10.08.0.

References

Affected packages

Ubuntu:22.04:LTS
ghostscript

Package

Name
ghostscript
Purl
pkg:deb/ubuntu/ghostscript?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

9.*
9.54.0~dfsg1-0ubuntu2
9.55.0~dfsg1-0ubuntu4
9.55.0~dfsg1-0ubuntu5
9.55.0~dfsg1-0ubuntu5.1
9.55.0~dfsg1-0ubuntu5.2
9.55.0~dfsg1-0ubuntu5.3
9.55.0~dfsg1-0ubuntu5.4
9.55.0~dfsg1-0ubuntu5.5
9.55.0~dfsg1-0ubuntu5.6
9.55.0~dfsg1-0ubuntu5.7
9.55.0~dfsg1-0ubuntu5.9
9.55.0~dfsg1-0ubuntu5.10
9.55.0~dfsg1-0ubuntu5.11
9.55.0~dfsg1-0ubuntu5.12
9.55.0~dfsg1-0ubuntu5.13
9.55.0~dfsg1-0ubuntu5.14

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "ghostscript",
            "binary_version":  "9.55.0~dfsg1-0ubuntu5.14"
        },
        {
            "binary_name":  "ghostscript-x",
            "binary_version":  "9.55.0~dfsg1-0ubuntu5.14"
        },
        {
            "binary_name":  "libgs9",
            "binary_version":  "9.55.0~dfsg1-0ubuntu5.14"
        },
        {
            "binary_name":  "libgs9-common",
            "binary_version":  "9.55.0~dfsg1-0ubuntu5.14"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-19547.json"
Ubuntu:24.04:LTS
ghostscript

Package

Name
ghostscript
Purl
pkg:deb/ubuntu/ghostscript?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

10.*
10.01.2~dfsg1-0ubuntu2
10.01.2~dfsg1-0ubuntu2.1
10.02.1~dfsg1-0ubuntu1
10.02.1~dfsg1-0ubuntu2
10.02.1~dfsg1-0ubuntu5
10.02.1~dfsg1-0ubuntu6
10.02.1~dfsg1-0ubuntu7
10.02.1~dfsg1-0ubuntu7.1
10.02.1~dfsg1-0ubuntu7.3
10.02.1~dfsg1-0ubuntu7.4
10.02.1~dfsg1-0ubuntu7.5
10.02.1~dfsg1-0ubuntu7.6
10.02.1~dfsg1-0ubuntu7.7
10.02.1~dfsg1-0ubuntu7.8
10.02.1~dfsg1-0ubuntu7.9

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "ghostscript",
            "binary_version":  "10.02.1~dfsg1-0ubuntu7.9"
        },
        {
            "binary_name":  "libgs-common",
            "binary_version":  "10.02.1~dfsg1-0ubuntu7.9"
        },
        {
            "binary_name":  "libgs10",
            "binary_version":  "10.02.1~dfsg1-0ubuntu7.9"
        },
        {
            "binary_name":  "libgs10-common",
            "binary_version":  "10.02.1~dfsg1-0ubuntu7.9"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-19547.json"
Ubuntu:26.04:LTS
ghostscript

Package

Name
ghostscript
Purl
pkg:deb/ubuntu/ghostscript?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

10.*
10.05.0dfsg1-0ubuntu4
10.05.0dfsg1-0ubuntu5
10.06.0~dfsg-3ubuntu1
10.06.0~dfsg-3ubuntu1.1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "ghostscript",
            "binary_version":  "10.06.0~dfsg-3ubuntu1.1"
        },
        {
            "binary_name":  "libgs-common",
            "binary_version":  "10.06.0~dfsg-3ubuntu1.1"
        },
        {
            "binary_name":  "libgs10",
            "binary_version":  "10.06.0~dfsg-3ubuntu1.1"
        },
        {
            "binary_name":  "libgs10-common",
            "binary_version":  "10.06.0~dfsg-3ubuntu1.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-19547.json"
Ubuntu:Pro:16.04:LTS
ghostscript

Package

Name
ghostscript
Purl
pkg:deb/ubuntu/ghostscript?arch=source&distro=esm-infra%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

9.*
9.16~dfsg~0-0ubuntu3
9.16~dfsg~0-0ubuntu4
9.18~dfsg~0-0ubuntu1
9.18~dfsg~0-0ubuntu2
9.18~dfsg~0-0ubuntu2.2
9.18~dfsg~0-0ubuntu2.3
9.18~dfsg~0-0ubuntu2.4
9.18~dfsg~0-0ubuntu2.6
9.18~dfsg~0-0ubuntu2.7
9.18~dfsg~0-0ubuntu2.8
9.18~dfsg~0-0ubuntu2.9
9.25~dfsg+1-0ubuntu0.16.04.1
9.25~dfsg+1-0ubuntu0.16.04.2
9.25~dfsg+1-0ubuntu0.16.04.3
9.26~dfsg+0-0ubuntu0.16.04.1
9.26~dfsg+0-0ubuntu0.16.04.3
9.26~dfsg+0-0ubuntu0.16.04.4
9.26~dfsg+0-0ubuntu0.16.04.5
9.26~dfsg+0-0ubuntu0.16.04.6
9.26~dfsg+0-0ubuntu0.16.04.7
9.26~dfsg+0-0ubuntu0.16.04.8
9.26~dfsg+0-0ubuntu0.16.04.9
9.26~dfsg+0-0ubuntu0.16.04.10
9.26~dfsg+0-0ubuntu0.16.04.11
9.26~dfsg+0-0ubuntu0.16.04.12
9.26~dfsg+0-0ubuntu0.16.04.13
9.26~dfsg+0-0ubuntu0.16.04.14
9.26~dfsg+0-0ubuntu0.16.04.14+esm1
9.26~dfsg+0-0ubuntu0.16.04.14+esm2
9.26~dfsg+0-0ubuntu0.16.04.14+esm3
9.26~dfsg+0-0ubuntu0.16.04.14+esm4
9.26~dfsg+0-0ubuntu0.16.04.14+esm5
9.26~dfsg+0-0ubuntu0.16.04.14+esm6
9.26~dfsg+0-0ubuntu0.16.04.14+esm7
9.26~dfsg+0-0ubuntu0.16.04.14+esm8
9.26~dfsg+0-0ubuntu0.16.04.14+esm9
9.26~dfsg+0-0ubuntu0.16.04.14+esm10

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "ghostscript",
            "binary_version":  "9.26~dfsg+0-0ubuntu0.16.04.14+esm10"
        },
        {
            "binary_name":  "ghostscript-x",
            "binary_version":  "9.26~dfsg+0-0ubuntu0.16.04.14+esm10"
        },
        {
            "binary_name":  "libgs9",
            "binary_version":  "9.26~dfsg+0-0ubuntu0.16.04.14+esm10"
        },
        {
            "binary_name":  "libgs9-common",
            "binary_version":  "9.26~dfsg+0-0ubuntu0.16.04.14+esm10"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-19547.json"
Ubuntu:Pro:18.04:LTS
ghostscript

Package

Name
ghostscript
Purl
pkg:deb/ubuntu/ghostscript?arch=source&distro=esm-infra%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

9.*
9.21~dfsg+1-0ubuntu3
9.22~dfsg+1-0ubuntu1
9.22~dfsg+1-0ubuntu1.1
9.22~dfsg+1-0ubuntu1.2
9.25~dfsg+1-0ubuntu0.18.04.1
9.25~dfsg+1-0ubuntu0.18.04.2
9.26~dfsg+0-0ubuntu0.18.04.1
9.26~dfsg+0-0ubuntu0.18.04.3
9.26~dfsg+0-0ubuntu0.18.04.4
9.26~dfsg+0-0ubuntu0.18.04.5
9.26~dfsg+0-0ubuntu0.18.04.6
9.26~dfsg+0-0ubuntu0.18.04.7
9.26~dfsg+0-0ubuntu0.18.04.8
9.26~dfsg+0-0ubuntu0.18.04.9
9.26~dfsg+0-0ubuntu0.18.04.10
9.26~dfsg+0-0ubuntu0.18.04.11
9.26~dfsg+0-0ubuntu0.18.04.12
9.26~dfsg+0-0ubuntu0.18.04.13
9.26~dfsg+0-0ubuntu0.18.04.14
9.26~dfsg+0-0ubuntu0.18.04.15
9.26~dfsg+0-0ubuntu0.18.04.16
9.26~dfsg+0-0ubuntu0.18.04.17
9.26~dfsg+0-0ubuntu0.18.04.18
9.26~dfsg+0-0ubuntu0.18.04.18+esm1
9.26~dfsg+0-0ubuntu0.18.04.18+esm2
9.26~dfsg+0-0ubuntu0.18.04.18+esm3
9.26~dfsg+0-0ubuntu0.18.04.18+esm4
9.26~dfsg+0-0ubuntu0.18.04.18+esm5

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "ghostscript",
            "binary_version":  "9.26~dfsg+0-0ubuntu0.18.04.18+esm5"
        },
        {
            "binary_name":  "ghostscript-x",
            "binary_version":  "9.26~dfsg+0-0ubuntu0.18.04.18+esm5"
        },
        {
            "binary_name":  "libgs9",
            "binary_version":  "9.26~dfsg+0-0ubuntu0.18.04.18+esm5"
        },
        {
            "binary_name":  "libgs9-common",
            "binary_version":  "9.26~dfsg+0-0ubuntu0.18.04.18+esm5"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-19547.json"
Ubuntu:Pro:20.04:LTS
ghostscript

Package

Name
ghostscript
Purl
pkg:deb/ubuntu/ghostscript?arch=source&distro=esm-infra%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

9.*
9.27~dfsg+0-0ubuntu3
9.27~dfsg+0-0ubuntu4
9.50~dfsg-5ubuntu1
9.50~dfsg-5ubuntu2
9.50~dfsg-5ubuntu3
9.50~dfsg-5ubuntu4
9.50~dfsg-5ubuntu4.1
9.50~dfsg-5ubuntu4.2
9.50~dfsg-5ubuntu4.3
9.50~dfsg-5ubuntu4.4
9.50~dfsg-5ubuntu4.5
9.50~dfsg-5ubuntu4.6
9.50~dfsg-5ubuntu4.7
9.50~dfsg-5ubuntu4.8
9.50~dfsg-5ubuntu4.9
9.50~dfsg-5ubuntu4.10
9.50~dfsg-5ubuntu4.11
9.50~dfsg-5ubuntu4.12
9.50~dfsg-5ubuntu4.13
9.50~dfsg-5ubuntu4.14
9.50~dfsg-5ubuntu4.15
9.50~dfsg-5ubuntu4.15+esm1
9.50~dfsg-5ubuntu4.15+esm2

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "ghostscript",
            "binary_version":  "9.50~dfsg-5ubuntu4.15+esm2"
        },
        {
            "binary_name":  "ghostscript-x",
            "binary_version":  "9.50~dfsg-5ubuntu4.15+esm2"
        },
        {
            "binary_name":  "libgs9",
            "binary_version":  "9.50~dfsg-5ubuntu4.15+esm2"
        },
        {
            "binary_name":  "libgs9-common",
            "binary_version":  "9.50~dfsg-5ubuntu4.15+esm2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-19547.json"