Описание
Security update for podofo
This update for podofo fixes the following issue:
- CVE-2026-44348: double-free in
compute_hash_to_sign()insrc/podofo/private/OpenSSLInternal_Ripped.cpp(bsc#1265320).
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP7
libpodofo-devel-1.0.2-150700.3.6.1
Ссылки
- Link for SUSE-SU-2026:2309-1
- E-Mail link for SUSE-SU-2026:2309-1
- SUSE Security Ratings
- SUSE Bug 1265320
- SUSE CVE CVE-2026-44348 page
Описание
PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFinal fails after buf has already been freed, the Error label frees buf a second time, causing heap corruption. This vulnerability is fixed in 1.0.4.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:libpodofo-devel-1.0.2-150700.3.6.1
Ссылки
- CVE-2026-44348
- SUSE Bug 1265320