Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian: Important Fix for Arbitrary Code Execution in pdfminer DLA-4374-2

debian lts
Calendar Grey January 8, 2026
Dist Debian Esm H88
Update on the critical security issue in pdfminer for Debian addressing potential code execution risks.
It was previously discovered that there was a potential arbitrary code execution in pdfminer, a tool for extracting information from PDF documents

Summary

Although a fix for this was released in pdfminer version
20200726-1+deb11u2 (via DLA-4374-1), upstream subsequently determined
that this mitigation was insufficient and a more comprehensive
mitigation that replaces the pickle-based mechanism entirely was
applied instead.

For Debian 11 bullseye, this updated fix has been released in
version 20200726-1+deb11u2.

We recommend that you upgrade your pdfminer packages.

For the detailed security status of pdfminer please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/pdfminer

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
important
Lowest
Low
Medium
High
Critical

Package: pdfminer
Version: 20200726-1+deb11u2
CVE ID: CVE-2025-64512
Debian Bug: 1120642

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here