#1149698 poppler: CVE-2026-102621

Package:
src:poppler
Source:
src:poppler
Submitter:
Salvatore Bonaccorso
Date:
2026-10-06 16:21:06 UTC
Severity:
normal
Tags:
#1149698#5
Date:
2026-10-02 12:05:27 UTC
From:
To:
Hi,

The following vulnerability was published for poppler.

CVE-2026-102621[0]:
| A vulnerability was identified in Freedesktop Poppler up to 26.08.0.
| Affected is the function SplashClip::clipToPath of the file
| splash/SplashClip.cc. Such manipulation leads to integer overflow.
| The attack can only be performed from a local environment. The
| exploit is publicly available and might be used. Upgrading to
| version 26.09.0 is able to address this issue. The name of the patch
| is 323c91036d99926a8b90dc14329f7b40aece22f8. It is recommended to
| upgrade the affected component.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102621
https://www.cve.org/CVERecord?id=CVE-2026-102621
[1] https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1763
[2] https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2325
[3] https://gitlab.freedesktop.org/poppler/poppler/-/commit/323c91036d99926a8b90dc14329f7b40aece22f8

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149698#14
Date:
2026-10-06 16:19:03 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
poppler, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1149698@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated poppler package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 17:58:35 +0200
Source: poppler
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 26.07.0-3
Distribution: unstable
Urgency: high
Maintainer: Debian freedesktop.org maintainers <pkg-freedesktop-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1148266 1149697 1149698
Changes:
 poppler (26.07.0-3) unstable; urgency=high
 .
   * Team upload
 .
   [ Marc Deslauriers ]
   * SECURITY UPDATE: overflow in FoFiTrueType::cvtSfnts
     - debian/patches/CVE-2026-102620.patch: Fix integer overflow in
       FoFiTrueType::cvtSfnts in fofi/FoFiTrueType.cc.
     - CVE-2026-102620 (Closes: #1149697)
   * SECURITY UPDATE: overflow in SplashClip::clipToPath
     - debian/patches/CVE-2026-102621.patch: Fix integer overflow in
       SplashClip::clipToPath in splash/SplashClip.cc.
     - CVE-2026-102621 (Closes: #1149698)
   * SECURITY UPDATE: null pointer deref issue
     - debian/patches/CVE-2026-93312.patch: Fix nullptr + number in
       poppler/JBIG2Stream.cc.
     - CVE-2026-93312
   * SECURITY UPDATE: overflow in JBIG2Stream::readCodeTableSeg
     - debian/patches/CVE-2026-93313.patch: Fix integer overflow in
       JBIG2Stream::readCodeTableSeg in poppler/JBIG2Stream.cc.
     - CVE-2026-93313
   * SECURITY UPDATE: overflow in FoFiTrueType::mapCodeToGID
     - debian/patches/CVE-2026-93314.patch: FoFiTrueType::mapCodeToGID: Improve
       b*12 overflow check in fofi/FoFiTrueType.cc.
     - CVE-2026-93314 (Closes: #1148266)
Checksums-Sha1:
 6b8e84f29366c8a48344e8890f83fd327a42733f 3778 poppler_26.07.0-3.dsc
 21dd188c5abe5893bf743f697d456a7e6501a2a1 42544 poppler_26.07.0-3.debian.tar.xz
 cff07084aff009a1fa844c1f631f9a881059f738 8997 poppler_26.07.0-3_source.buildinfo
Checksums-Sha256:
 cb2d4e2f34d7b02f5c3d30383a5b477d22ba14314bfca7392091f6858f2c57c7 3778 poppler_26.07.0-3.dsc
 127d549f22048fb2198234f005e9eebcb6c242570e39f6829183cc9b0c4ed556 42544 poppler_26.07.0-3.debian.tar.xz
 cf13e8b296ce6e5dbb2887f52f17bcc73be47ef3e9915cf780d85f1db370710d 8997 poppler_26.07.0-3_source.buildinfo
Files:
 f0559d025982c50f56a6501ab3066aeb 3778 devel optional poppler_26.07.0-3.dsc
 b36c2a7fcdb8440d8bdfc1e99dac5ff3 42544 devel optional poppler_26.07.0-3.debian.tar.xz
 5c77e7278c58144c22d67f9574cf5579 8997 devel optional poppler_26.07.0-3_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmrFGwIACgkQ5mx3Wuv+
bH0k0w//YX1RyHUpy5CuX2cHhi79zZBLM2oeXdWWFvZrWujpir1mgs43uzMpTENL
sjis4J8OxqCWGtW0DYgccNju/VxUyZk6YAJIS4NBiN5X+kFNRJz5qXuhRXGXM5HC
BEGH81CAbGDcv7yh4aNLFvhSGALokQos+7X059jDRcjHTxU+5rh+AMBKBKUSj79H
xZfzQxBzcO5mBLSMekIMFlGmQo9Um1JOpVSzef0BnxC03fBWCmGTJzYTO6uwGM25
X/QPt+qAbWhjjcX1Ma25gs4wY8Boi6gDPFK31CKkrvOheYtxTM2X0vPOYRC3aNvY
YmN5PHjKFY9NjIlaayCPrrPVG/rceIJoTIu6t+rEI8HJd9e/zoetLnapUFy5By9E
9x5hFLXE5zAFHz5xqvgJT/jpMUXXiH9yHA+vWc5XEZGFk47Nit/gK/+zxBoywEkr
HOcGTHOVQPru7ERVAq00P8jtdE8e+ZHcxNn047ue9bWDJYWrkiuUDxrkFycjOHZX
l4cCuZS1O2KMBNwY9AG6eGNGHuhAgkq29jXvjYN9xLlCEtX1E4LPuyWeGH0M+yor
1arQzQh75sfkF4XddlgrncRvJxWh/iTKRLK2vK8thVxTNAj7So1YBg1D/nKIBvGF
UPhRkVyQ9dACuzaQmvrdrNnOdDNHZbmx4zed09UJWb8XDnOvjtU=
=STWq
-----END PGP SIGNATURE-----