Impact
A flaw in Poppler’s SplashClip::clipToPath function allows signed integer overflow when processing certain PDF content. The overflow can corrupt memory during rendering, potentially leading to a denial of service or, in some situations, arbitrary code execution. The weakness is rooted in signed/unsigned arithmetic errors, as identified by CWE-189 and CWE-190.
Affected Systems
The vulnerability is present in the Freedesktop Poppler library up to version 26.08.0. Users should identify installations of Poppler earlier than 26.09.0 and plan for an upgrade. The affected product is the core Poppler library used by PDF rendering tools on Linux and other operating systems.
Risk and Exploitability
The CVSS score of 4.8 indicates a medium severity with a local attack vector. Because the exploit requires local file access and is publicly available, an attacker who can place a crafted PDF on the affected system may trigger the overflow. The EPSS score is not available, so the current exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. Given these factors, the risk is considered moderate, primarily limiting damage to compromised or reused local environments.
OpenCVE Enrichment