Back to vendor advisories
Ubuntu Security NoticesUSN-8894-1

USN-8894-1: poppler vulnerabilities

Severity not listed 5 CVEs Published Oct 7, 2026 at 1:00 PM UTC

Summary

It was discovered that Poppler had an integer overflow in FoFiTrueType::cvtSfnts. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-102620)

It was discovered that Poppler had an integer overflow in SplashClip::clipToPath. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-102621)

It was discovered that Poppler had a null pointer dereference in JBIG2Stream. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service. (CVE-2026-93312)

It was discovered that Poppler had an integer overflow in JBIG2Stream::readCodeTableSeg. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-93313)

It was discovered that Poppler had an integer overflow in FoFiTrueType::mapCodeToGID. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-93314)

Products covered

A separate affected-products list was not included in the collected bulletin.

Remediation

Separate remediation guidance was not included in the collected bulletin.

CVEs in this advisory 5

Updates

  1. Published by Ubuntu

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.