rootpwn

medium · CVSS v3 4.3

CVE-2026-93312

A null pointer dereference in Poppler 26.07.0’s JBIG2Stream::rewind can be triggered remotely, causing a crash in PDF rendering. The flaw is

Overview

A null pointer dereference in Poppler 26.07.0’s JBIG2Stream::rewind can be triggered remotely, causing a crash in PDF rendering. The flaw is limited to the Poppler library and does not directly expose data. Updating to 26.08.0 mitigates the issue.

Description

A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised.

Impact

The vulnerability leads to a denial‑of‑service condition by crashing the PDF rendering process. It does not compromise confidentiality or integrity directly. Systems that process untrusted PDFs—such as desktop environments, document editors, and web browsers using Poppler—are impacted. Attackers could disrupt user workflows or server‑side PDF services.

Remediation

1. Upgrade Poppler to version 26.08.0 or later; the patch commit 5e49250f13b0390edeb3f90eb4c02c9941f97067 addresses the issue.\n2. Use your package manager or vendor update channel to apply the update.\n3. If an upgrade is not immediately possible, isolate PDF processing in a sandbox or container and restrict access to untrusted PDFs.\n4. Monitor system logs for repeated null‑pointer dereference errors and enforce strict input validation for PDF files.

Risk context

The CVSS v3 score of 4.3 indicates a medium severity vulnerability that primarily causes denial of service. No EPSS data is available, but the exploit is publicly published, so defenders should apply the patch promptly to avoid potential disruption.

Affected products

  • Freedesktop Poppler
  • Poppler 26.07.0
  • Poppler 26.08.0
  • Linux PDF viewers
  • LibreOffice

Scores

Severity
medium
CVSS v2
5
CVSS v3
4.3
CVSS v4
EPSS

Poppler

← All CVEs