PT-2026-45444 · Poppler+4 · Poppler+4

·

CVE-2026-10118

·

Published

2026-06-01

·

Updated

2026-07-14

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Poppler (affected versions not specified)
Description A flaw in the Splash backend allows a remote attacker to trigger an integer overflow in the tilingPatternFill() function by using a specially crafted PDF file. This overflow causes an undersized heap memory allocation, which enables an out-of-bounds write. This can lead to arbitrary code execution, information disclosure, or denial of service within the application processing the PDF.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:24984
ALSA-2026:24985
ALSA-2026:25058
BDU:2026-10558
CVE-2026-10118
ECHO-C3B3-3988-EEB5
OESA-2026-2648
OESA-2026-2649
OESA-2026-2650
RHSA-2026:24984
RHSA-2026:24985
RHSA-2026:25058
RHSA-2026:27720
RHSA-2026:27721
RHSA-2026:27722
RHSA-2026:27723
RHSA-2026:27724
RHSA-2026:27725
RHSA-2026:27727
RHSA-2026:29952
RHSA-2026:30044
RHSA-2026:30134
USN-8400-1

Affected Products

Linuxmint
Poppler
Red Os
Rocky Linux
Ubuntu