CVE-2023-36807: Infinite Loop when reading malformed objects in pypdf

Published Jun 30, 2023
·
Updated

Impact An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted metadata from such a malformed PDF.

Patches The issue was fixed with https://github.com/py-pdf/pypdf/pull/1331

Workarounds If you cannot update your version of PyPDF2 (preferably to pypdf>3.1.0 as PyPDF2 is deprecated), you should modify PyPDF2/generic/datastructures.py::readobject.

Replace:

python else: # number object OR indirect reference peek = stream.read(20) stream.seek(-len(peek), 1) # reset to start if IndirectPattern.match(peek) is not None: return IndirectObject.readfromstream(stream, pdf) else: return NumberObject.readfromstream(stream)

by

python elif tok in b"0123456789+-.": # number object OR indirect reference peek = stream.read(20) stream.seek(-len(peek), 1) # reset to start if IndirectPattern.match(peek) is not None: return IndirectObject.readfromstream(stream, pdf) else: return NumberObject.readfromstream(stream) else: raise PdfReadError( f"Invalid Elementary Object starting with {tok} @{stream.tell()}" )

References pypdf issue #1329 pypdf PR #1331

Other sources

pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In version 2.10.5 an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted metadata from such a malformed PDF. Versions prior to 2.10.5 throw an error, but do not hang forever. This issue was fixed with https://github.com/py-pdf/pypdf/pull/1331 which has been included in release 2.10.6. Users are advised to upgrade. Users unable to upgrade should modify PyPDF2/generic/datastructures.py::readobject to an an error throwing case. See GHSA-hm9v-vj3r-r55m for details.

MITRE

Affected Software

2 affected componentsFixes available
pip/PyPDF2=2.10.5
2.10.6
Pypdf Project Pypdf=2.10.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/PyPDF2 to a version that resolves this vulnerability.

    Fixed in 2.10.6
  2. Upgrade

    Upgrade pypdf to a version that resolves this vulnerability.

    Fixed in 2.10.6Patch pypdf PR #1331
  3. Upgrade

    Upgrade pypdf to a version that resolves this vulnerability.

    Fixed in 3.1.0
  4. Configuration

    If you cannot update, modify `PyPDF2/generic/_data_structures.py::read_object` to an error-throwing case to avoid the infinite loop when reading malformed PDFs (issue: Infinite Loop when reading malformed objects in pypdf).

    PyPDF2/pypdf (pypdf/pypdf) PyPDF2/generic/_data_structures.py::read_object = Modify read_object to an error-throwing case instead of looping on malformed objects (e.g., for the IndirectPattern path, throw PdfReadError rather than continuing to read/loop)

Event History

Jun 30, 2023
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
10:19 PM

Frequently Asked Questions

1

What is the impact of CVE-2023-36807?

This vulnerability can cause an infinite loop in a PDF, which can use 100% of a CPU core.

2

How does CVE-2023-36807 affect the affected software?

The affected software can be blocked by a crafted PDF, causing an infinite loop.

3

What versions of PyPDF2 are affected by CVE-2023-36807?

PyPDF2 version 2.10.5 is affected by this vulnerability.

4

How can I fix CVE-2023-36807?

Update to PyPDF2 version 2.10.6 to fix this vulnerability.

5

Where can I find more information about CVE-2023-36807?

You can find more information about CVE-2023-36807 on the GitHub security advisory page and the NIST vulnerability detail page.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203