Description
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading to version 26.09.0 is able to address this issue. The name of the patch is 323c91036d99926a8b90dc14329f7b40aece22f8. It is recommended to upgrade the affected component.
Published: 2026-09-29
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Local integer overflow
Action: Apply Update
AI Analysis

Impact

A flaw in Poppler’s SplashClip::clipToPath function allows signed integer overflow when processing certain PDF content. The overflow can corrupt memory during rendering, potentially leading to a denial of service or, in some situations, arbitrary code execution. The weakness is rooted in signed/unsigned arithmetic errors, as identified by CWE-189 and CWE-190.

Affected Systems

The vulnerability is present in the Freedesktop Poppler library up to version 26.08.0. Users should identify installations of Poppler earlier than 26.09.0 and plan for an upgrade. The affected product is the core Poppler library used by PDF rendering tools on Linux and other operating systems.

Risk and Exploitability

The CVSS score of 4.8 indicates a medium severity with a local attack vector. Because the exploit requires local file access and is publicly available, an attacker who can place a crafted PDF on the affected system may trigger the overflow. The EPSS score is not available, so the current exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. Given these factors, the risk is considered moderate, primarily limiting damage to compromised or reused local environments.

Generated by OpenCVE AI on September 30, 2026 at 08:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Poppler library to version 26.09.0 or newer to apply the published fix.
  • Update all software components that embed or link against the affected Poppler version to ensure they use the patched library.
  • If an immediate upgrade is not feasible, restrict the execution of PDF rendering operations to trusted environments or implement sandboxing of untrusted documents to mitigate local exploitation risk.

Generated by OpenCVE AI on September 30, 2026 at 08:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Tue, 29 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading to version 26.09.0 is able to address this issue. The name of the patch is 323c91036d99926a8b90dc14329f7b40aece22f8. It is recommended to upgrade the affected component.
Title Freedesktop Poppler SplashClip.cc clipToPath integer overflow
First Time appeared Freedesktop
Freedesktop poppler
Weaknesses CWE-189
CWE-190
CPEs cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*
Vendors & Products Freedesktop
Freedesktop poppler
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Freedesktop Poppler
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-29T21:30:11.612Z

Reserved: 2026-09-29T14:30:20.158Z

Link: CVE-2026-102621

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T22:17:07.867

Modified: 2026-09-29T22:17:07.867

Link: CVE-2026-102621

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-29T21:30:11Z

Links: CVE-2026-102621 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:15:17Z

Weaknesses