CVE-2025-50422Reachable Assertion in Cairo

Severity
2.9LOWNVD
EPSS
0.0%
top 92.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 4
Latest updateAug 12

Description

Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 1.4 | Impact: 1.4

🔴Vulnerability Details

2
OSV
CVE-2025-50422: Cairo through 12025-08-04
GHSA
GHSA-6f98-2v97-grfv: An issue was discovered in freedesktop poppler v252025-08-04

📋Vendor Advisories

3
Microsoft
Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.2025-08-12
Red Hat
poppler: Poppler crash on malformed input2025-08-04
Debian
CVE-2025-50422: cairo - Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face...2025