Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-10118

Опубликовано: 01 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.8

Описание

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the tilingPatternFill function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

РелизСтатусПримечание
devel

not-affected

26.01.0-5
esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

released

22.02.0-2ubuntu0.13
noble

released

24.02.0-1ubuntu9.9
questing

released

25.03.0-10ubuntu0.2
resolute

released

26.01.0-2ubuntu0.1
upstream

released

26.01.0-4.1

Показывать по

EPSS

Процентиль: 14%
0.00231
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
около 2 месяцев назад

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

CVSS3: 7.8
nvd
около 2 месяцев назад

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

CVSS3: 7.8
debian
около 2 месяцев назад

A flaw was found in Poppler's Splash backend. A remote attacker could ...

rocky
около 2 месяцев назад

Important: poppler security update

rocky
около 2 месяцев назад

Important: poppler security update

EPSS

Процентиль: 14%
0.00231
Низкий

7.8 High

CVSS3