AI analysis
Freedesktop Poppler through 26.08.0 has an integer overflow in SplashClip::clipToPath in splash/SplashClip.cc. It is triggered by manipulating clip-path handling and can be exploited only from a local environment, with low privileges and no user interaction. Scored impact is limited to low availability of the local process, with no confidentiality or integrity impact. Distributions and applications shipping Poppler at or below 26.08.0 are affected, including those covered by Ubuntu USN-8894-1. The CNA states that an exploit is publicly available and CVSS 4.0 exploit maturity is Proof-of-Concept; the issue is not in CISA KEV, so confirmed in-the-wild use is not known.
What to do: Upgrade Poppler to 26.09.0 or later (patch 323c91036d99926a8b90dc14329f7b40aece22f8) and apply distribution updates such as Ubuntu USN-8894-1. Until then, avoid processing untrusted PDFs with Poppler-based tools on shared or multi-user systems, because the issue is local and can disrupt availability of the rendering process.
Affected
| Freedesktop Poppler | up to 26.08.0 |
Estimated exposure
masstens of millions of Linux installations (library dependency) — Poppler is the standard PDF rendering library on major Linux distributions (Debian, Ubuntu, Fedora and others) and a common dependency of document viewers and poppler-utils; Ubuntu published USN-8894-1. No public install census exists, so…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading to version 26.09.0 is able to address this issue. The name of the patch is 323c91036d99926a8b90dc14329f7b40aece22f8. It is recommended to upgrade the affected component.