PT-2026-45444 · Poppler+2 · Poppler+2

Aisle In

·

Published

2026-06-01

·

Updated

2026-06-10

·

CVE-2026-10118

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Poppler (affected versions not specified)
Description A flaw in the Splash backend allows a remote attacker to trigger an integer overflow in the tilingPatternFill() function by using a specially crafted PDF file. This overflow causes an undersized heap memory allocation, which enables an out-of-bounds write. This can lead to arbitrary code execution, information disclosure, or denial of service within the application processing the PDF.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:24984
ALSA-2026:24985
ALSA-2026:25058
CVE-2026-10118
ECHO-C3B3-3988-EEB5
USN-8400-1

Affected Products

Poppler
Rocky Linux
Ubuntu