CVE-2026-102621: Freedesktop Poppler SplashClip.cc clipToPath integer overflow
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading to version 26.09.0 is able to address this issue. The name of the patch is 323c91036d99926a8b90dc14329f7b40aece22f8. It is recommended to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Freedesktop Popplerto a version that resolves this vulnerability.Fixed in 26.09.0Patch 323c91036d99926a8b90dc14329f7b40aece22f8
Event History
Frequently Asked Questions
Who is exposed to this issue?
Only local attackers can exploit it. The supplied severity vector indicates that an attacker also needs low-level privileges; remote exploitation is not indicated.
Which versions should be upgraded?
Freedesktop Poppler versions up to 26.08.0 are affected. Upgrade to version 26.09.0, which addresses the issue.
Is public exploit code available?
Yes. The vulnerability information states that an exploit is publicly available and may be used.
What patch identifies the fix?
The fix is identified by patch 323c91036d99926a8b90dc14329f7b40aece22f8.