Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: poppler

Found 1 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-10118
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 1 week, 5 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    13 packages
    • poppler_data
    • libsForQt5.poppler
    • kdePackages.poppler
    • qt6Packages.poppler
    • plasma5Packages.poppler
    • haskellPackages.gi-poppler
    • python312Packages.poppler-qt5
    • python313Packages.poppler-qt5
    • python314Packages.poppler-qt5
    • zathuraPkgs.zathura_pdf_poppler
    • python312Packages.python-poppler
    • python313Packages.python-poppler
    • python314Packages.python-poppler
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Poppler: integer overflow in poppler splashoutputdev::tilingpatternfill leads to heap buffer overflow via unchecked dimension multiplication

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

Affected products

poppler
compat-poppler022

Matching in nixpkgs

Ignored packages (13)

Package maintainers

Patch: https://gitlab.freedesktop.org/poppler/poppler/-/commit/8352264766652b98336e92359a70b3161a9ab97a