Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-52886

Опубликовано: 02 июл. 2025
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

Poppler is a PDF rendering library. Versions prior to 25.06.0 use std::atomic_int for reference counting. Because std::atomic_int is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.

A use-after-free vulnerability has been discovered in the PDF rendering library, stemming from a reference counting flaw. This issue allows an attacker, by providing specially crafted malicious input, to overflow a reference counter which subsequently leads to a use-after-free condition. While the exploitation of this vulnerability in practice requires a significant amount of time to achieve, it nonetheless presents a risk of memory corruption, potentially leading to unpredictable program behavior, crashes, or, in more severe scenarios, could lay the groundwork for arbitrary code execution.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10popplerFix deferred
Red Hat Enterprise Linux 10poppler-dataFix deferred
Red Hat Enterprise Linux 6popplerFix deferred
Red Hat Enterprise Linux 6poppler-dataFix deferred
Red Hat Enterprise Linux 7compat-poppler022Fix deferred
Red Hat Enterprise Linux 7popplerFix deferred
Red Hat Enterprise Linux 7poppler-dataFix deferred
Red Hat Enterprise Linux 8popplerFix deferred
Red Hat Enterprise Linux 8poppler-dataFix deferred
Red Hat Enterprise Linux 9popplerFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2375930poppler: Poppler Use After Free Vulnerability

EPSS

Процентиль: 19%
0.00061
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.

CVSS3: 5.9
nvd
4 месяца назад

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.

CVSS3: 5.9
debian
4 месяца назад

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std ...

suse-cvrf
4 месяца назад

Security update for poppler

suse-cvrf
4 месяца назад

Security update for poppler

EPSS

Процентиль: 19%
0.00061
Низкий

4 Medium

CVSS3