CVE-2026-93312: Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Freedesktop Popplerto a version that resolves this vulnerability.Fixed in 26.08.0Patch 5e49250f13b0390edeb3f90eb4c02c9941f97067
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue can be initiated remotely and requires no privileges, but it requires user interaction. The published exploit may be used to trigger the null pointer dereference.
What is the expected security impact?
Successful exploitation affects availability only, causing a low availability impact. The supplied vector indicates no confidentiality or integrity impact.
Which version should be deployed to remediate the issue?
Upgrade Freedesktop Poppler to version 26.08.0. The associated patch is 5e49250f13b0390edeb3f90eb4c02c9941f97067.