high · CVSS v3 6.3 · CVSS v4 5.3
CVE-2026-93313
An integer overflow vulnerability exists in Freedesktop Poppler version 26.07.0 within the JBIG2Stream::readCodeTableSeg function in poppler
Overview
An integer overflow vulnerability exists in Freedesktop Poppler version 26.07.0 within the JBIG2Stream::readCodeTableSeg function in poppler/JBIG2Stream.cc. This flaw can be triggered remotely via malicious PDF files containing crafted JBIG2 streams. It matters because successful exploitation could lead to application crashes or potentially arbitrary code execution in environments processing untrusted documents.
Description
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named eb87cf711563894649bd0c365baa479401dc6d51. To fix this issue, it is recommended to deploy a patch.
Impact
This vulnerability primarily impacts systems, applications, and services that utilize the Poppler PDF rendering library to process untrusted documents. The integrity and availability of the affected host process are at risk, with potential confidentiality impacts if memory corruption leads to code execution. Users and administrators operating software with embedded Poppler components are vulnerable.
Remediation
Apply the official vendor patch referenced by commit eb87cf711563894649bd0c365baa479401dc6d51. Upgrade Poppler to a secure version containing the fix for the JBIG2Stream integer overflow. As a defense-in-depth measure, isolate PDF rendering workloads within sandboxed environments with restricted privileges.
Risk context
The vulnerability is rated as high severity with a CVSS v3 score of 6.3 and CVSS v4 score of 5.3. Because public exploit details are available, defenders should treat this issue with elevated urgency, prioritizing patching for systems handling untrusted PDF content.
Affected products
- Freedesktop Poppler 26.07.0
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 6.3
- CVSS v4
- 5.3
- EPSS
- —