RHSA-2026:30044: Important: poppler security update
Important: poppler security update
Other sources
Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince.Security Fix(es): poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication (CVE-2026-10118) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/popplerto a version that resolves this vulnerability.Fixed in 0.26.5-44.el7_9 - Upgrade
Upgrade
redhat/poppler-cppto a version that resolves this vulnerability.Fixed in 0.26.5-44.el7_9 - Upgrade
Upgrade
redhat/poppler-cpp-develto a version that resolves this vulnerability.Fixed in 0.26.5-44.el7_9 - Upgrade
Upgrade
redhat/poppler-debuginfoto a version that resolves this vulnerability.Fixed in 0.26.5-44.el7_9 - Upgrade
Upgrade
redhat/poppler-demosto a version that resolves this vulnerability.Fixed in 0.26.5-44.el7_9 - Upgrade
Upgrade
redhat/poppler-develto a version that resolves this vulnerability.Fixed in 0.26.5-44.el7_9 - Upgrade
Upgrade
redhat/poppler-glibto a version that resolves this vulnerability.Fixed in 0.26.5-44.el7_9 - Upgrade
Upgrade
redhat/poppler-glib-develto a version that resolves this vulnerability.Fixed in 0.26.5-44.el7_9 - Upgrade
Upgrade
redhat/poppler-qtto a version that resolves this vulnerability.Fixed in 0.26.5-44.el7_9 - Upgrade
Upgrade
redhat/poppler-qt-develto a version that resolves this vulnerability.Fixed in 0.26.5-44.el7_9 - Upgrade
Upgrade
redhat/poppler-utilsto a version that resolves this vulnerability.Fixed in 0.26.5-44.el7_9
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:30044?
The severity of RHSA-2026:30044 is rated as high with a score of 7.
What are the security issues addressed in RHSA-2026:30044?
RHSA-2026:30044 addresses an integer overflow in Poppler that leads to a heap buffer overflow.
How do I fix RHSA-2026:30044?
To fix RHSA-2026:30044, you should update the affected Poppler packages to the latest version provided by Red Hat.
What applications rely on the Poppler library affected by RHSA-2026:30044?
Applications such as Evince utilize the Poppler library that is affected by the vulnerabilities in RHSA-2026:30044.
What is Poppler and its role in relation to RHSA-2026:30044?
Poppler is a Portable Document Format rendering library used by applications to handle PDF files, and it is implicated in the vulnerabilities outlined in RHSA-2026:30044.