USN-8894-1: poppler vulnerabilities
Ubuntu's USN-8894-1 fixes Poppler overflows and a null dereference that can crash or run code.
Ubuntu security notice USN-8894-1 describes vulnerabilities in Poppler. CVE-2026-102620 is an integer overflow in FoFiTrueType::cvtSfnts and CVE-2026-102621 is an integer overflow in SplashClip::clipToPath; either could crash Poppler or allow arbitrary code execution. CVE-2026-93312 is a null pointer dereference in JBIG2Stream that can cause a denial of service. The published notice text is truncated after introducing a further issue, and no exploitation is reported.
- CVE-2026-102620 and CVE-2026-102621 are integer overflows that may allow code execution.
- CVE-2026-93312 is a JBIG2Stream null dereference that can crash Poppler.
- USN-8894-1 is a routine Ubuntu advisory; exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2026-1026201.9—Integer overflow in Freedesktop Poppler TrueType handlingpublished · Freedesktop Poppler
- CVE-2026-1026211.9—Integer overflow in Freedesktop Poppler SplashClippublished · Freedesktop Poppler
It was discovered that Poppler had an integer overflow in FoFiTrueType::cvtSfnts. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-102620) It was discovered that Poppler had an integer overflow in SplashClip::clipToPath. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-102621) It was discovered that Poppler had a null pointer dereference in JBIG2Stream. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service. (CVE-2026-93312) It was discovered that Poppler had an…
This source does not provide full text. Read it at ubuntu.com.