Impact
The vulnerability resides in the FoFiTrueType::mapCodeToGID function of Poppler 26.07.0. Manipulation of the segCnt argument can cause an unsigned integer overflow, which may lead to undefined behavior such as memory corruption or erroneous execution. This weakness is classified as CWE‑189 (Integer Overflow or Wraparound) and CWE‑190 (Integer Overflow). The CVE description notes that the attack can be launched remotely and that the exploit has been publicly disclosed, indicating that an attacker could potentially craft a malicious TrueType font to trigger the overflow.
Affected Systems
Poppler library version 26.07.0 from Freedesktop. The affected code resides in the fofi/FoFiTrueType.cc file. Earlier or later releases that have not yet merged the documented patch commit (ed2a5538cf0a8d3ff908191eda9b73f91a5f952a) remain vulnerable.
Risk and Exploitability
The CVSS score is 5.3, reflecting a moderate impact. EPSS indicates a very low probability of exploitation (<1%). The vulnerability is not listed in the CISA KEV catalog. An attacker can remotely manipulate the segCnt parameter in a TrueType font to trigger the overflow, but successful exploitation would likely require precise conditions and is not widely reported. Overall risk is moderate due to the remote launch and public disclosure, but low exploitation likelihood according to EPSS.
OpenCVE Enrichment
Ubuntu USN