> USN-8894-1: poppler vulnerabilities
[DATE: 07/10/2026 13:00]
[LANGUAGE: EN]
It was discovered that Poppler had an integer overflow in
FoFiTrueType::cvtSfnts. An attacker could possibly use this issue to
cause Poppler to crash, resulting in a denial of service, or execute
arbitrary code.
(CVE-2026-102620)
It was discovered that Poppler had an integer overflow in
SplashClip::clipToPath. An attacker could possibly use this issue to
cause Poppler to crash, resulting in a denial of service, or execute
arbitrary code.
(CVE-2026-102621)
It was discovered that Poppler had a null pointer dereference in
JBIG2Stream. An attacker could possibly use this issue to cause
Poppler to crash, resulting in a denial of service.
(CVE-2026-93312)
It was discovered that Poppler had an integer overflow in
JBIG2Stream::readCodeTableSeg. An attacker could possibly use this
issue to cause Poppler to crash, resulting in a denial of service,
or execute arbitrary code.
(CVE-2026-93313)
It was discovered that Poppler had an integer overflow in
FoFiTrueType::mapCodeToGID. An attacker could possibly use this
issue to cause Poppler to crash, resulting in a denial of service,
or execute arbitrary code.
(CVE-2026-93314)