Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46529

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 7.8

Описание

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is shell/ev-application.c:ev_spawn, which builds a command line from attacker-controlled PDF link-destination fields without applying g_shell_quote. The cmdline is then handed to g_app_info_create_from_commandline, which shell-parses it back into argv — splitting any embedded --gtk-module=PATH into a separate argv element. GTK then dlopen()s the path during init, running any __attribute__((constructor)) it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT --checkpoint-action injection in comics-document.c, fixed in 1.6.2) but in a different code path (shell/ev-application.c) that the original patch did not touch.

A flaw was found in Atril, Evince and Xreader. A malicious link inside a specially crafted PDF document can cause arbitrary code execution when clicked due to improper quoting of attacker-controlled PDF link-destination fields during remote go-to (/GoToR) actions. This issue allows an attacker to execute arbitrary code with the privileges of the user that clicked on the embedded link.

Отчет

To exploit this issue, an attacker needs to convince a user to open a specially crafted PDF document and to click on a malicious link inside the document, limiting its exposure. Also, this flaw allows an attacker to execute arbitrary code with the privileges of the user that clicked on the embedded link, which is usually a low-privileged user account, limiting its impact. However, an attacker can package a single file that is simultaneously a valid PDF document and a valid ELF shared library, making the exploit self-contained and exploitable via a single click. Due to these reasons, this vulnerability has been rated with an important severity.

Меры по смягчению последствий

To mitigate this vulnerability, do not click on links inside PDF documents from untrusted or unverified sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6evinceWill not fix
Red Hat Enterprise Linux 7evinceAffected
Red Hat Enterprise Linux 8evinceFixedRHSA-2026:2899824.06.2026
Red Hat Enterprise Linux 9evinceFixedRHSA-2026:2781922.06.2026
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsevinceFixedRHSA-2026:3911514.07.2026
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsevinceFixedRHSA-2026:3341630.06.2026
Red Hat Enterprise Linux 9.6 Extended Update SupportevinceFixedRHSA-2026:3316929.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=2487669atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 месяцев назад

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1...

CVSS3: 7.8
nvd
около 2 месяцев назад

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26

CVSS3: 7.8
debian
около 2 месяцев назад

Atril Document Viewer is the default document reader of the MATE deskt ...

suse-cvrf
около 1 месяца назад

Security update for papers

suse-cvrf
2 месяца назад

Security update for evince

7.8 High

CVSS3