CVE-2026-93653

NameCVE-2026-93653
DescriptionA denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that drives an excessively long loop in the pattern-fill scanline routine, without a corresponding memory allocation. An attacker could exploit this by supplying a malicious PDF to an application that renders it via Poppler's Splash backend, causing the rendering process to consume 100% CPU for an attacker-controlled, extended duration.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148398

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
poppler (PTS)bookworm22.12.0-2+deb12u2vulnerable
bookworm (security)22.12.0-2+deb12u3vulnerable
trixie25.03.0-5+deb13u4vulnerable
trixie (security)25.03.0-5+deb13u3vulnerable
forky26.07.0-2vulnerable
sid26.07.0-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
popplersource(unstable)(unfixed)1148398

Notes

[trixie] - poppler <no-dsa> (Minor issue)
[bookworm] - poppler <postponed> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=2537005

Search for package or bug name: Reporting problems