Impact
A null pointer dereference occurs in Poppler’s JBIG2Stream::rewind function when processing a document that invokes the rewind operation. The flaw allows an attacker to cause the receiving application to terminate unexpectedly, resulting in a denial‑of‑service condition. The issue is categorized as CWE‑476 and CWE‑404 and is quantified with a CVSS score of 5.3.
Affected Systems
Freedesktop Poppler version 26.07.0 is affected by the vulnerability in JBIG2Stream.cc. The patch in commit 5e49250f13b0390edeb3f90eb4c02c9941f97067 implements the fix and is available in version 26.08.0 and later.
Risk and Exploitability
The exploit has been published and can be triggered by a malicious input file, which is likely to be delivered remotely. Based on the description, it is inferred that the attacker can supply a specially crafted PDF that invokes the rewind method, though no remote code execution or privilege escalation is indicated. The EPSS score of less than 1% suggests a low probability of large‑scale exploitation, and the vulnerability is not listed in the CISA KEV catalog. Consequently, the principal risk remains a single application crash rather than a system compromise.
OpenCVE Enrichment
Ubuntu USN