CVE-2026-10118

Discovered by AISLEPUBLISHEDCWE-190

Description

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

CVSS Base Scores

CVSS v3.1(Primary)
7.8

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionStatus
Red HatPoppler0:24.02.0-7.el10_2.2unaffected
Red HatPoppler0:24.02.0-7.el10_0.1
Red HatPoppler0:0.22.5-7.el7_9
Red HatPoppler0:0.26.5-44.el7_9
Red HatPoppler0:20.11.0-14.el8_10
Red HatPoppler0:20.11.0-2.el8_4.3
Red HatPoppler0:20.11.0-5.el8_6.1
Red HatPoppler0:20.11.0-7.el8_8.1
Red HatPoppler0:21.01.0-24.el9_8.1
Red HatPoppler0:21.01.0-15.el9_2.1
Red HatPoppler0:21.01.0-20.el9_4.1
Red HatPoppler0:21.01.0-22.el9_6.1
Red HatPoppler1782352950
Red HatPoppler1782352919
Red HatPoppler1782353093
Red HatPoppler1782352847
Red HatPoppler26.06.0-0.1.hum1

Credits

  • This issue was discovered by AISLE Research and AISLE in partnership with Red Hat.

References