CVE-2018-9918: High severity Qpdf Project Qpdf vulnerability
Last updated 25 August 2025
Other sources
libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDFDictionary classes, because nesting in direct objects is not restricted.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qpdfto a version that resolves this vulnerability.Fixed in 10.1.0-1Fixed in 11.3.0-1+deb12u1Fixed in 12.2.0-1Fixed in 12.3.2-1 - Upgrade
Upgrade
qpdfto a version that resolves this vulnerability.Fixed in 8.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9918?
CVE-2018-9918 has been classified as a denial of service vulnerability due to stack exhaustion.
How do I fix CVE-2018-9918?
To fix CVE-2018-9918, upgrade to version 10.1.0-1 or later for Debian or ensure you're using qpdf versions 8.0.2-3~14.04.1 or later for Ubuntu.
What software is affected by CVE-2018-9918?
CVE-2018-9918 affects qpdf versions up to and including 8.0.2 on various Ubuntu and Debian distributions.
Can CVE-2018-9918 be exploited remotely?
Yes, CVE-2018-9918 can be exploited by remote attackers to cause a denial of service.
What kind of issue does CVE-2018-9918 cause?
CVE-2018-9918 causes stack exhaustion leading to denial of service.