High severity7.5NVD Advisory· Published Sep 23, 2025· Updated Jun 17, 2026
CVE-2025-55780
CVE-2025-55780
Description
A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- MuPDF/MuPDFdescription
- osv-coords2 versionspkg:rpm/opensuse/mupdf&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mupdf&distro=openSUSE%20Leap%2016.0
< 1.27.1-1.1+ 1 more
- (no CPE)range: < 1.27.1-1.1
- (no CPE)range: < 1.27.2-bp160.1.1
Patches
Vulnerability mechanics
References
3- bugs.ghostscript.com/show_bug.cginvdIssue TrackingThird Party Advisory
- github.com/ISH2YU/CVE-2025-55780/tree/mainnvdThird Party Advisory
- cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/nvdPermissions Required
News mentions
0No linked articles in our index yet.