rootpwn

medium · CVSS v3 4.3

CVE-2026-93311

Freedesktop Poppler 26.07.0 contains an integer overflow in SampledFunction::SampledFunction in poppler/Function.cc, triggered by handling t

Overview

Freedesktop Poppler 26.07.0 contains an integer overflow in SampledFunction::SampledFunction in poppler/Function.cc, triggered by handling the BitsPerSample argument. The issue can be reached remotely when processing crafted PDF content. It matters because Poppler is widely used in PDF rendering and document-processing workflows, and the description states an exploit is public.

Description

A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSample results in integer overflow. The attack may be performed from remote. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

Impact

The flaw is an integer overflow that can lead to memory corruption while parsing PDF sample-function data. Availability is the most direct concern, with possible denial of service during PDF processing. If memory corruption is successfully leveraged, confidentiality and integrity could also be affected in systems that process untrusted PDFs. Users, document conversion services, PDF viewers, and backend services using Poppler 26.07.0 are the primary impacted parties.

Remediation

Apply the vendor-provided patch or upgrade to a Poppler release that fixes the integer overflow in SampledFunction::SampledFunction. Until patched, restrict processing of untrusted PDFs, run PDF parsing in a sandboxed or least-privilege environment, and monitor for abnormal behavior or crashes in Poppler-based services.

Affected products

  • Freedesktop Poppler 26.07.0
  • Poppler PDF library
  • Applications embedding Poppler 26.07.0

Scores

Severity
medium
CVSS v2
5
CVSS v3
4.3
CVSS v4
EPSS

← All CVEs