AI analysis
Freedesktop Poppler 26.06.0, 26.07.0, and 26.08.0 contain an integer overflow in FoFiTrueType::cvtSfnts in fofi/FoFiTrueType.cc, which handles TrueType font data. The flaw is triggered by manipulating that conversion path and can be reached only with local access and low privileges. CVSS 4.0 scores the impact as low integrity only (1.9), with no confidentiality or availability effect on the vulnerable component. Anyone running those Poppler releases, including systems that pull the library through Linux distribution packages, is affected. The advisory states that an exploit has been publicly disclosed and CVSS exploit maturity is Proof-of-Concept; it is not in the CISA KEV catalog, so widespread in-the-wild exploitation is not indicated.
What to do: Install the upstream patch 245d3c6823377755f2c1d5fdddd010279c6ed94d, or the Poppler package update from your distribution (Ubuntu tracks this in USN-8894-1). Until then, avoid processing untrusted PDFs with affected Poppler builds; this is a local, low-severity issue and can follow normal patch cycles.
Affected
| Freedesktop Poppler | 26.06.0, 26.07.0, 26.08.0 |
Estimated exposure
massTens of millions of Linux systems that ship Poppler (order-of-magnitude estimate) — Poppler is the standard PDF rendering library shipped by major Linux distributions and used by desktop viewers and PDF tools; Ubuntu USN-8894-1 shows distro packaging, so affected installs are estimated in the tens of millions or more…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 245d3c6823377755f2c1d5fdddd010279c6ed94d. It is suggested to install a patch to address this issue.