Impact
The vulnerability is an integer overflow in Poppler’s JBIG2Stream::readCodeTableSeg function. By supplying a specially crafted JBIG2 stream an attacker can trigger the overflow, causing the library to behave unexpectedly and resulting in a crash that interrupts service. The weakness aligns with CWE-189 and CWE-190. Because the input can be supplied remotely, the primary impact is a remote denial of service.
Affected Systems
Affected systems include Freedesktop Poppler version 26.07.0. No other affected versions are explicitly listed. Any installation using that release or earlier unpatched builds is at risk.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity with a focus on availability. The EPSS score of less than 1% indicates a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the exploit is publicly available and can be executed remotely by providing malicious JBIG2 content, so the practical risk to systems that process untrusted input remains real.
OpenCVE Enrichment
Ubuntu USN