We believe that the bug you reported is fixed in the latest version of
poppler, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1149697@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated poppler package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 17:58:35 +0200
Source: poppler
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 26.07.0-3
Distribution: unstable
Urgency: high
Maintainer: Debian freedesktop.org maintainers <pkg-freedesktop-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1148266 1149697 1149698
Changes:
poppler (26.07.0-3) unstable; urgency=high
.
* Team upload
.
[ Marc Deslauriers ]
* SECURITY UPDATE: overflow in FoFiTrueType::cvtSfnts
- debian/patches/CVE-2026-102620.patch: Fix integer overflow in
FoFiTrueType::cvtSfnts in fofi/FoFiTrueType.cc.
- CVE-2026-102620 (Closes: #1149697)
* SECURITY UPDATE: overflow in SplashClip::clipToPath
- debian/patches/CVE-2026-102621.patch: Fix integer overflow in
SplashClip::clipToPath in splash/SplashClip.cc.
- CVE-2026-102621 (Closes: #1149698)
* SECURITY UPDATE: null pointer deref issue
- debian/patches/CVE-2026-93312.patch: Fix nullptr + number in
poppler/JBIG2Stream.cc.
- CVE-2026-93312
* SECURITY UPDATE: overflow in JBIG2Stream::readCodeTableSeg
- debian/patches/CVE-2026-93313.patch: Fix integer overflow in
JBIG2Stream::readCodeTableSeg in poppler/JBIG2Stream.cc.
- CVE-2026-93313
* SECURITY UPDATE: overflow in FoFiTrueType::mapCodeToGID
- debian/patches/CVE-2026-93314.patch: FoFiTrueType::mapCodeToGID: Improve
b*12 overflow check in fofi/FoFiTrueType.cc.
- CVE-2026-93314 (Closes: #1148266)
Checksums-Sha1:
6b8e84f29366c8a48344e8890f83fd327a42733f 3778 poppler_26.07.0-3.dsc
21dd188c5abe5893bf743f697d456a7e6501a2a1 42544 poppler_26.07.0-3.debian.tar.xz
cff07084aff009a1fa844c1f631f9a881059f738 8997 poppler_26.07.0-3_source.buildinfo
Checksums-Sha256:
cb2d4e2f34d7b02f5c3d30383a5b477d22ba14314bfca7392091f6858f2c57c7 3778 poppler_26.07.0-3.dsc
127d549f22048fb2198234f005e9eebcb6c242570e39f6829183cc9b0c4ed556 42544 poppler_26.07.0-3.debian.tar.xz
cf13e8b296ce6e5dbb2887f52f17bcc73be47ef3e9915cf780d85f1db370710d 8997 poppler_26.07.0-3_source.buildinfo
Files:
f0559d025982c50f56a6501ab3066aeb 3778 devel optional poppler_26.07.0-3.dsc
b36c2a7fcdb8440d8bdfc1e99dac5ff3 42544 devel optional poppler_26.07.0-3.debian.tar.xz
5c77e7278c58144c22d67f9574cf5579 8997 devel optional poppler_26.07.0-3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmrFGwIACgkQ5mx3Wuv+
bH0k0w//YX1RyHUpy5CuX2cHhi79zZBLM2oeXdWWFvZrWujpir1mgs43uzMpTENL
sjis4J8OxqCWGtW0DYgccNju/VxUyZk6YAJIS4NBiN5X+kFNRJz5qXuhRXGXM5HC
BEGH81CAbGDcv7yh4aNLFvhSGALokQos+7X059jDRcjHTxU+5rh+AMBKBKUSj79H
xZfzQxBzcO5mBLSMekIMFlGmQo9Um1JOpVSzef0BnxC03fBWCmGTJzYTO6uwGM25
X/QPt+qAbWhjjcX1Ma25gs4wY8Boi6gDPFK31CKkrvOheYtxTM2X0vPOYRC3aNvY
YmN5PHjKFY9NjIlaayCPrrPVG/rceIJoTIu6t+rEI8HJd9e/zoetLnapUFy5By9E
9x5hFLXE5zAFHz5xqvgJT/jpMUXXiH9yHA+vWc5XEZGFk47Nit/gK/+zxBoywEkr
HOcGTHOVQPru7ERVAq00P8jtdE8e+ZHcxNn047ue9bWDJYWrkiuUDxrkFycjOHZX
l4cCuZS1O2KMBNwY9AG6eGNGHuhAgkq29jXvjYN9xLlCEtX1E4LPuyWeGH0M+yor
1arQzQh75sfkF4XddlgrncRvJxWh/iTKRLK2vK8thVxTNAj7So1YBg1D/nKIBvGF
UPhRkVyQ9dACuzaQmvrdrNnOdDNHZbmx4zed09UJWb8XDnOvjtU=
=STWq
-----END PGP SIGNATURE-----