---
title: "CVE-2025-9394\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-9394?format=md
keywords: index, follow
---

# CVE-2025-9394

Publication date 24 August 2025

Last updated 8 September 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2025-9394?format=md#impact-score)

Toggle side navigation

## Description

A flaw has been found in PoDoFo 1.1.0-dev. This issue affects the function
PdfTokenizer::DetermineDataType of the file
src/podofo/main/PdfTokenizer.cpp of the component PDF Dictionary Parser.
Executing manipulation can lead to use after free. It is possible to launch
the attack on the local host. The exploit has been published and may be
used. This patch is called 22d16cb142f293bf956f66a4d399cdd65576d36c. A
patch should be applied to remediate this issue.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| libpodofo | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2025-9394?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| libpodofo | * Upstream:   [eeef7c7](https://github.com/vim/vim/commit/eeef7c77436a78cd27047b0f5fa6925d56de3cb0) |

## Severity score breakdown

CVSS version:

CVSS v4.0

[CVSS v4.0](https://ubuntu.com/security/CVE-2025-9394?format=md)
[CVSS v3.0](https://ubuntu.com/security/CVE-2025-9394?format=md)

**Base score**

1.9 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Attack requirements | None |
  | Privileges required | Low |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | Low |
  | Vulnerable system - Integrity impact | Low |
  | Vulnerable system - Availability impact | Low |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 1.9 · Low |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-9394)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-9394)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-9394)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-9394)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-9394>
* <https://drive.google.com/file/d/1edJH17GAiK9R441Gjyj8tiV_2ptoL16U/view?usp=sharing>
* <https://vuldb.com/?ctiid.321227>
* <https://vuldb.com/?id.321227>
* <https://vuldb.com/?submit.632364>
* <https://vuldb.com/?submit.632365>
