Description
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Application Crash)
Action: Immediate Patch
AI Analysis

Impact

A null pointer dereference occurs in Poppler’s JBIG2Stream::rewind function when processing a document that invokes the rewind operation. The flaw allows an attacker to cause the receiving application to terminate unexpectedly, resulting in a denial‑of‑service condition. The issue is categorized as CWE‑476 and CWE‑404 and is quantified with a CVSS score of 5.3.

Affected Systems

Freedesktop Poppler version 26.07.0 is affected by the vulnerability in JBIG2Stream.cc. The patch in commit 5e49250f13b0390edeb3f90eb4c02c9941f97067 implements the fix and is available in version 26.08.0 and later.

Risk and Exploitability

The exploit has been published and can be triggered by a malicious input file, which is likely to be delivered remotely. Based on the description, it is inferred that the attacker can supply a specially crafted PDF that invokes the rewind method, though no remote code execution or privilege escalation is indicated. The EPSS score of less than 1% suggests a low probability of large‑scale exploitation, and the vulnerability is not listed in the CISA KEV catalog. Consequently, the principal risk remains a single application crash rather than a system compromise.

Generated by OpenCVE AI on September 19, 2026 at 21:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Poppler update to version 26.08.0 or later so that the vulnerable rewind function is fixed.
  • Rebuild or reinstall any applications that link to Poppler to ensure they load the corrected library.
  • If an immediate update cannot be applied, process untrusted PDF files in a sandbox or disable JBIG2 support to prevent the rewind routine from being invoked.

Generated by OpenCVE AI on September 19, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8894-1 poppler vulnerabilities
History

Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised.
Title Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference
First Time appeared Freedesktop
Freedesktop poppler
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*
Vendors & Products Freedesktop
Freedesktop poppler
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Freedesktop Poppler
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T18:23:02.769Z

Reserved: 2026-09-17T17:13:08.412Z

Link: CVE-2026-93312

cve-icon Vulnrichment

Updated: 2026-09-22T18:22:20.943Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T01:16:56.710

Modified: 2026-09-22T19:16:57.607

Link: CVE-2026-93312

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T00:45:12Z

Links: CVE-2026-93312 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:15:06Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference