Description
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called ed2a5538cf0a8d3ff908191eda9b73f91a5f952a. It is advisable to implement a patch to correct this issue.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Integer overflow in FoFiTrueType::mapCodeToGID may allow exploitation by manipulating the segCnt argument
Action: Patch
AI Analysis

Impact

The vulnerability resides in the FoFiTrueType::mapCodeToGID function of Poppler 26.07.0. Manipulation of the segCnt argument can cause an unsigned integer overflow, which may lead to undefined behavior such as memory corruption or erroneous execution. This weakness is classified as CWE‑189 (Integer Overflow or Wraparound) and CWE‑190 (Integer Overflow). The CVE description notes that the attack can be launched remotely and that the exploit has been publicly disclosed, indicating that an attacker could potentially craft a malicious TrueType font to trigger the overflow.

Affected Systems

Poppler library version 26.07.0 from Freedesktop. The affected code resides in the fofi/FoFiTrueType.cc file. Earlier or later releases that have not yet merged the documented patch commit (ed2a5538cf0a8d3ff908191eda9b73f91a5f952a) remain vulnerable.

Risk and Exploitability

The CVSS score is 5.3, reflecting a moderate impact. EPSS indicates a very low probability of exploitation (<1%). The vulnerability is not listed in the CISA KEV catalog. An attacker can remotely manipulate the segCnt parameter in a TrueType font to trigger the overflow, but successful exploitation would likely require precise conditions and is not widely reported. Overall risk is moderate due to the remote launch and public disclosure, but low exploitation likelihood according to EPSS.

Generated by OpenCVE AI on September 19, 2026 at 21:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch that merges commit ed2a5538cf0a8d3ff908191eda9b73f91a5f952a
  • Upgrade to the latest available Poppler release that contains the fix
  • Validate or sanitize input font data to ensure segCnt values remain within expected bounds

Generated by OpenCVE AI on September 19, 2026 at 21:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8894-1 poppler vulnerabilities
History

Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 22 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called ed2a5538cf0a8d3ff908191eda9b73f91a5f952a. It is advisable to implement a patch to correct this issue.
Title Freedesktop Poppler FoFiTrueType.cc mapCodeToGID integer overflow
First Time appeared Freedesktop
Freedesktop poppler
Weaknesses CWE-189
CWE-190
CPEs cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*
Vendors & Products Freedesktop
Freedesktop poppler
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Freedesktop Poppler
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T02:01:37.143Z

Reserved: 2026-09-17T17:13:15.208Z

Link: CVE-2026-93314

cve-icon Vulnrichment

Updated: 2026-09-22T02:01:31.726Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T02:17:08.600

Modified: 2026-09-22T03:16:58.083

Link: CVE-2026-93314

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T01:30:10Z

Links: CVE-2026-93314 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:15:06Z

Weaknesses