Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-24985

Опубликовано: 16 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-24985: poppler security update (IMPORTANT)

[24.02.0-7.el10_2.2]

  • Fix integer overflow in tilingPatternFill (CVE-2026-10118)
  • Bump NVR for MR
  • Resolves: RHEL-180565

[24.02.0-7.el10_2.1]

  • Fix integer overflow in tilingPatternFill (CVE-2026-10118)
  • Resolves: RHEL-180565

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

poppler

24.02.0-7.el10_2.2

poppler-cpp

24.02.0-7.el10_2.2

poppler-cpp-devel

24.02.0-7.el10_2.2

poppler-devel

24.02.0-7.el10_2.2

poppler-glib

24.02.0-7.el10_2.2

poppler-glib-devel

24.02.0-7.el10_2.2

poppler-glib-doc

24.02.0-7.el10_2.2

poppler-qt6

24.02.0-7.el10_2.2

poppler-qt6-devel

24.02.0-7.el10_2.2

poppler-utils

24.02.0-7.el10_2.2

Oracle Linux x86_64

poppler

24.02.0-7.el10_2.2

poppler-cpp

24.02.0-7.el10_2.2

poppler-cpp-devel

24.02.0-7.el10_2.2

poppler-devel

24.02.0-7.el10_2.2

poppler-glib

24.02.0-7.el10_2.2

poppler-glib-devel

24.02.0-7.el10_2.2

poppler-glib-doc

24.02.0-7.el10_2.2

poppler-qt6

24.02.0-7.el10_2.2

poppler-qt6-devel

24.02.0-7.el10_2.2

poppler-utils

24.02.0-7.el10_2.2

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 месяцев назад

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

CVSS3: 7.8
redhat
около 2 месяцев назад

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

CVSS3: 7.8
nvd
около 2 месяцев назад

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

CVSS3: 7.8
debian
около 2 месяцев назад

A flaw was found in Poppler's Splash backend. A remote attacker could ...

rocky
около 2 месяцев назад

Important: poppler security update