https://seclists.org/oss-sec/2026/q2/643: Evince/Atril/Xader command injection CVE-2026-46529
Published May 21, 2026
·Updated
Affected Software
3 affected components
Gnome Evince
MATE Atril
Linux Mint Xreader
Frequently Asked Questions
1
What is the severity of CVE-2026-46529?
CVE-2026-46529 is classified as a critical vulnerability due to its potential for remote command injection.
2
How do I fix CVE-2026-46529?
To fix CVE-2026-46529, update to the latest versions of Evince, Atril, or Xreader as provided by the respective maintainers.
3
What software is affected by CVE-2026-46529?
CVE-2026-46529 affects Gnome Evince, MATE Atril, and Linux Mint Xreader.
4
What types of attacks are possible with CVE-2026-46529?
CVE-2026-46529 allows attackers to execute arbitrary commands on the system through malicious PDF files.
5
Is there an exploit available for CVE-2026-46529?
Yes, details include scripts for crafting malicious polyglot PDFs that can exploit CVE-2026-46529.