CVE-2026-10118

NameCVE-2026-10118
DescriptionA flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1138708

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
poppler (PTS)bullseye20.09.0-3.1+deb11u1vulnerable
bullseye (security)20.09.0-3.1+deb11u2vulnerable
bookworm22.12.0-2+deb12u1vulnerable
trixie25.03.0-5+deb13u2vulnerable
forky25.03.0-11.1vulnerable
sid26.01.0-4.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
popplersource(unstable)26.01.0-4.11138708

Notes

https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1715
https://gitlab.freedesktop.org/poppler/poppler/-/commit/8352264766652b98336e92359a70b3161a9ab97a

Search for package or bug name: Reporting problems