RHSA-2026:29952: Important: compat-poppler022 security update
Compatibility package with poppler 0.22 libraries.Security Fix(es): poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication (CVE-2026-10118) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: compat-poppler022 security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/compat-poppler022to a version that resolves this vulnerability.Fixed in 0.22.5-7.el7_9 - Upgrade
Upgrade
redhat/compat-poppler022-cppto a version that resolves this vulnerability.Fixed in 0.22.5-7.el7_9 - Upgrade
Upgrade
redhat/compat-poppler022-debuginfoto a version that resolves this vulnerability.Fixed in 0.22.5-7.el7_9 - Upgrade
Upgrade
redhat/compat-poppler022-glibto a version that resolves this vulnerability.Fixed in 0.22.5-7.el7_9 - Upgrade
Upgrade
redhat/compat-poppler022-qtto a version that resolves this vulnerability.Fixed in 0.22.5-7.el7_9 - Upgrade
Upgrade
compat-poppler022to a version that resolves this vulnerability.Patch CVE-2026-10118
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:29952?
The severity of RHSA-2026:29952 is rated high with a CVSS score of 7.
How do I fix RHSA-2026:29952?
To fix RHSA-2026:29952, update to the latest version of the compat-poppler022 package as provided by your Red Hat repositories.
What is the vulnerability identified in RHSA-2026:29952?
RHSA-2026:29952 addresses an integer overflow in Poppler that could lead to a heap buffer overflow.
What are the affected products for RHSA-2026:29952?
Affected products include redhat/compat-poppler022 and its related packages such as compat-poppler022-cpp and compat-poppler022-qt.
Is there a known exploit for RHSA-2026:29952?
While the specific details of exploit availability are not disclosed, the nature of the vulnerability suggests potential for exploitation if not patched.