USN-8894-1: poppler vulnerabilities
It was discovered that Poppler had an integer overflow in
FoFiTrueType::cvtSfnts. An attacker could possibly use this issue to
cause Poppler to crash, resulting in a denial of service, or execute
arbitrary code.
(CVE-2026-102620)
It was discovered that Poppler had an integer overflow in
SplashClip::clipToPath. An attacker could possibly use this issue to
cause Poppler to crash, resulting in a denial of service, or execute
arbitrary code.
(CVE-2026-102621)
It was discovered that Poppler had a null pointer dereference in
JBIG2Stream. An attacker could possibly use this issue to cause
Poppler to crash, resulting in a denial of service.
(CVE-2026-93312)
It was discovered that Poppler had an integer overflow in
JBIG2Stream::readCodeTableSeg. An attacker could possibly use this
issue to cause Poppler to crash, resulting in a denial of service,
or execute arbitrary code.
(CVE-2026-93313)
It was discovered that Poppler had an integer overflow in
FoFiTrueType::mapCodeToGID. An attacker could possibly use this
issue to cause Poppler to crash, resulting in a denial of service,
or execute arbitrary code.
(CVE-2026-93314)