USN-8894-1: poppler vulnerabilities
Ubuntu's USN-8894-1 fixes Poppler overflows and a null dereference that can crash or run code.
Ubuntu security notice USN-8894-1 describes vulnerabilities in Poppler. CVE-2026-102620 is an integer overflow in FoFiTrueType::cvtSfnts and CVE-2026-102621 is an integer overflow in SplashClip::clipToPath; either could crash Poppler or allow arbitrary code execution. CVE-2026-93312 is a null pointer dereference in JBIG2Stream that can cause a denial of service. The published notice text is truncated after introducing a further issue, and no exploitation is reported.