rootpwn

high · CVSS v3 6.3 · CVSS v4 5.3

CVE-2026-93313

An integer overflow vulnerability exists in Freedesktop Poppler version 26.07.0 within the JBIG2Stream::readCodeTableSeg function in poppler

Overview

An integer overflow vulnerability exists in Freedesktop Poppler version 26.07.0 within the JBIG2Stream::readCodeTableSeg function in poppler/JBIG2Stream.cc. This flaw can be triggered remotely via malicious PDF files containing crafted JBIG2 streams. It matters because successful exploitation could lead to application crashes or potentially arbitrary code execution in environments processing untrusted documents.

Description

A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named eb87cf711563894649bd0c365baa479401dc6d51. To fix this issue, it is recommended to deploy a patch.

Impact

This vulnerability primarily impacts systems, applications, and services that utilize the Poppler PDF rendering library to process untrusted documents. The integrity and availability of the affected host process are at risk, with potential confidentiality impacts if memory corruption leads to code execution. Users and administrators operating software with embedded Poppler components are vulnerable.

Remediation

Apply the official vendor patch referenced by commit eb87cf711563894649bd0c365baa479401dc6d51. Upgrade Poppler to a secure version containing the fix for the JBIG2Stream integer overflow. As a defense-in-depth measure, isolate PDF rendering workloads within sandboxed environments with restricted privileges.

Risk context

The vulnerability is rated as high severity with a CVSS v3 score of 6.3 and CVSS v4 score of 5.3. Because public exploit details are available, defenders should treat this issue with elevated urgency, prioritizing patching for systems handling untrusted PDF content.

Affected products

  • Freedesktop Poppler 26.07.0

Scores

Severity
high
CVSS v2
7.5
CVSS v3
6.3
CVSS v4
5.3
EPSS

integer-overflow poppler pdf jbig2 remote-execution freedesktop

← All CVEs