CVE-2026-93312

NameCVE-2026-93312
DescriptionA flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
poppler (PTS)bookworm22.12.0-2+deb12u2vulnerable
bookworm (security)22.12.0-2+deb12u3vulnerable
trixie25.03.0-5+deb13u4vulnerable
trixie (security)25.03.0-5+deb13u3vulnerable
forky, sid26.07.0-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
popplersource(unstable)(unfixed)

Notes

https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1759
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2314
Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/5e49250f13b0390edeb3f90eb4c02c9941f97067 (poppler-26.08.0)

Search for package or bug name: Reporting problems