RHSA-2026:42692: Important: evince security update
Important: evince security update
Other sources
The evince packages provide a simple multi-page document viewer for Portable Document Format (PDF), PostScript (PS), Encapsulated PostScript (EPS) files, and, with additional back-ends, also the Device Independent File format (DVI) files.Security Fix(es): atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen (CVE-2026-46529) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/evinceto a version that resolves this vulnerability.Fixed in 3.28.4-16.el8_8.1 - Upgrade
Upgrade
redhat/evince-browser-pluginto a version that resolves this vulnerability.Fixed in 3.28.4-16.el8_8.1 - Upgrade
Upgrade
redhat/evince-browser-plugin-debuginfoto a version that resolves this vulnerability.Fixed in 3.28.4-16.el8_8.1 - Upgrade
Upgrade
redhat/evince-debuginfoto a version that resolves this vulnerability.Fixed in 3.28.4-16.el8_8.1 - Upgrade
Upgrade
redhat/evince-debugsourceto a version that resolves this vulnerability.Fixed in 3.28.4-16.el8_8.1 - Upgrade
Upgrade
redhat/evince-libsto a version that resolves this vulnerability.Fixed in 3.28.4-16.el8_8.1 - Upgrade
Upgrade
redhat/evince-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.28.4-16.el8_8.1 - Upgrade
Upgrade
redhat/evince-nautilusto a version that resolves this vulnerability.Fixed in 3.28.4-16.el8_8.1 - Upgrade
Upgrade
redhat/evince-nautilus-debuginfoto a version that resolves this vulnerability.Fixed in 3.28.4-16.el8_8.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:42692?
The severity of RHSA-2026:42692 is classified as high, with a score of 7.
What does the RHSA-2026:42692 update address?
The RHSA-2026:42692 update addresses security vulnerabilities in the evince document viewer software.
How do I fix RHSA-2026:42692?
To fix RHSA-2026:42692, you should update your evince packages to the latest version available in your Red Hat repository.
What software is affected by RHSA-2026:42692?
The affected software includes various evince packages, such as evince, evince-browser-plugin, and their respective debuginfo packages.
When was RHSA-2026:42692 published?
RHSA-2026:42692 was published on July 21, 2026.