Source: poppler
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerabilities were published for poppler.

CVE-2026-93312[0]:
| A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is
| the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc.
| This manipulation causes null pointer dereference. It is possible to
| initiate the attack remotely. The exploit has been published and may
| be used. Upgrading to version 26.08.0 is recommended to address this
| issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067.
| Upgrading the affected component is advised.

https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1759
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2314
Fixed by: 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/5e49250f13b0390edeb3f90eb4c02c9941f97067
 (poppler-26.08.0)

CVE-2026-93313[1]:
| A vulnerability was found in Freedesktop Poppler 26.07.0. The
| impacted element is the function JBIG2Stream::readCodeTableSeg of
| the file poppler/JBIG2Stream.cc. Performing a manipulation results
| in integer overflow. The attack can be initiated remotely. The
| exploit has been made public and could be used. The patch is named
| eb87cf711563894649bd0c365baa479401dc6d51. To fix this issue, it is
| recommended to deploy a patch.

https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1760
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2322
Fixed by: 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/eb87cf711563894649bd0c365baa479401dc6d51

CVE-2026-93314[2]:
| A vulnerability was determined in Freedesktop Poppler 26.07.0. This
| affects the function FoFiTrueType::mapCodeToGID of the file
| fofi/FoFiTrueType.cc. Executing a manipulation of the argument
| segCnt can lead to integer overflow. The attack can be launched
| remotely. The exploit has been publicly disclosed and may be
| utilized. This patch is called
| ed2a5538cf0a8d3ff908191eda9b73f91a5f952a. It is advisable to
| implement a patch to correct this issue.

https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1761
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2315
Fixed by: 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/ed2a5538cf0a8d3ff908191eda9b73f91a5f952a
 (poppler-26.08.0)
 

If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-93312
    https://www.cve.org/CVERecord?id=CVE-2026-93312
[1] https://security-tracker.debian.org/tracker/CVE-2026-93313
    https://www.cve.org/CVERecord?id=CVE-2026-93313
[2] https://security-tracker.debian.org/tracker/CVE-2026-93314
    https://www.cve.org/CVERecord?id=CVE-2026-93314

Please adjust the affected versions in the BTS as needed.

Reply via email to