Source: poppler X-Debbugs-CC: [email protected] Severity: important Tags: security
Hi, The following vulnerabilities were published for poppler. CVE-2026-93312[0]: | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is | the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. | This manipulation causes null pointer dereference. It is possible to | initiate the attack remotely. The exploit has been published and may | be used. Upgrading to version 26.08.0 is recommended to address this | issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. | Upgrading the affected component is advised. https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1759 https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2314 Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/5e49250f13b0390edeb3f90eb4c02c9941f97067 (poppler-26.08.0) CVE-2026-93313[1]: | A vulnerability was found in Freedesktop Poppler 26.07.0. The | impacted element is the function JBIG2Stream::readCodeTableSeg of | the file poppler/JBIG2Stream.cc. Performing a manipulation results | in integer overflow. The attack can be initiated remotely. The | exploit has been made public and could be used. The patch is named | eb87cf711563894649bd0c365baa479401dc6d51. To fix this issue, it is | recommended to deploy a patch. https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1760 https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2322 Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/eb87cf711563894649bd0c365baa479401dc6d51 CVE-2026-93314[2]: | A vulnerability was determined in Freedesktop Poppler 26.07.0. This | affects the function FoFiTrueType::mapCodeToGID of the file | fofi/FoFiTrueType.cc. Executing a manipulation of the argument | segCnt can lead to integer overflow. The attack can be launched | remotely. The exploit has been publicly disclosed and may be | utilized. This patch is called | ed2a5538cf0a8d3ff908191eda9b73f91a5f952a. It is advisable to | implement a patch to correct this issue. https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1761 https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2315 Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/ed2a5538cf0a8d3ff908191eda9b73f91a5f952a (poppler-26.08.0) If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-93312 https://www.cve.org/CVERecord?id=CVE-2026-93312 [1] https://security-tracker.debian.org/tracker/CVE-2026-93313 https://www.cve.org/CVERecord?id=CVE-2026-93313 [2] https://security-tracker.debian.org/tracker/CVE-2026-93314 https://www.cve.org/CVERecord?id=CVE-2026-93314 Please adjust the affected versions in the BTS as needed.

