Description
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named eb87cf711563894649bd0c365baa479401dc6d51. To fix this issue, it is recommended to deploy a patch.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an integer overflow in Poppler’s JBIG2Stream::readCodeTableSeg function. By supplying a specially crafted JBIG2 stream an attacker can trigger the overflow, causing the library to behave unexpectedly and resulting in a crash that interrupts service. The weakness aligns with CWE-189 and CWE-190. Because the input can be supplied remotely, the primary impact is a remote denial of service.

Affected Systems

Affected systems include Freedesktop Poppler version 26.07.0. No other affected versions are explicitly listed. Any installation using that release or earlier unpatched builds is at risk.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity with a focus on availability. The EPSS score of less than 1% indicates a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the exploit is publicly available and can be executed remotely by providing malicious JBIG2 content, so the practical risk to systems that process untrusted input remains real.

Generated by OpenCVE AI on September 19, 2026 at 22:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch corresponding to commit eb87cf711563894649bd0c365baa479401dc6d51 to correct the integer overflow
  • Upgrade to the latest stable Poppler release that includes the fix or a newer version where the issue is resolved
  • Restrict or disable JBIG2 stream processing for untrusted documents, for example by configuring applications to reject JBIG2 content until a safe handling mechanism is available

Generated by OpenCVE AI on September 19, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8894-1 poppler vulnerabilities
History

Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named eb87cf711563894649bd0c365baa479401dc6d51. To fix this issue, it is recommended to deploy a patch.
Title Freedesktop Poppler JBIG2Stream.cc readCodeTableSeg integer overflow
First Time appeared Freedesktop
Freedesktop poppler
Weaknesses CWE-189
CWE-190
CPEs cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*
Vendors & Products Freedesktop
Freedesktop poppler
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Freedesktop Poppler
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T12:54:25.677Z

Reserved: 2026-09-17T17:13:11.939Z

Link: CVE-2026-93313

cve-icon Vulnrichment

Updated: 2026-09-18T12:53:57.538Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T02:17:08.420

Modified: 2026-09-18T13:23:37.403

Link: CVE-2026-93313

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T01:15:13Z

Links: CVE-2026-93313 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:00:10Z

Weaknesses