Описание
ELSA-2026-24985: poppler security update (IMPORTANT)
[24.02.0-7.el10_2.2]
- Fix integer overflow in tilingPatternFill (CVE-2026-10118)
- Bump NVR for MR
- Resolves: RHEL-180565
[24.02.0-7.el10_2.1]
- Fix integer overflow in tilingPatternFill (CVE-2026-10118)
- Resolves: RHEL-180565
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
poppler
24.02.0-7.el10_2.2
poppler-cpp
24.02.0-7.el10_2.2
poppler-cpp-devel
24.02.0-7.el10_2.2
poppler-devel
24.02.0-7.el10_2.2
poppler-glib
24.02.0-7.el10_2.2
poppler-glib-devel
24.02.0-7.el10_2.2
poppler-glib-doc
24.02.0-7.el10_2.2
poppler-qt6
24.02.0-7.el10_2.2
poppler-qt6-devel
24.02.0-7.el10_2.2
poppler-utils
24.02.0-7.el10_2.2
Oracle Linux x86_64
poppler
24.02.0-7.el10_2.2
poppler-cpp
24.02.0-7.el10_2.2
poppler-cpp-devel
24.02.0-7.el10_2.2
poppler-devel
24.02.0-7.el10_2.2
poppler-glib
24.02.0-7.el10_2.2
poppler-glib-devel
24.02.0-7.el10_2.2
poppler-glib-doc
24.02.0-7.el10_2.2
poppler-qt6
24.02.0-7.el10_2.2
poppler-qt6-devel
24.02.0-7.el10_2.2
poppler-utils
24.02.0-7.el10_2.2
Связанные CVE
Связанные уязвимости
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
A flaw was found in Poppler's Splash backend. A remote attacker could ...