PT-2025-27644 · Poppler+7 · Poppler+7
Kevin Backhouse
+1
·
Published
2025-06-03
·
Updated
2025-11-13
·
CVE-2025-52886
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Poppler versions prior to 25.06.0
Description:
The issue is related to the use of
std::atomic int for reference counting in the Poppler PDF rendering library. Since std::atomic int is only 32 bits, it is possible to overflow the reference count, which can trigger a use-after-free.Recommendations:
For versions prior to 25.06.0, update to version 25.06.0 to resolve the issue.
Exploit
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Poppler
Red Os
Suse
Ubuntu