Impact
A denial‑of‑service flaw exists in the Poppler Splash backend. A crafted PDF that uses a tiling‑pattern geometry near the 32‑bit integer boundary causes the library to calculate an attacker‑controlled repeat count. This drives an excessively long loop in the pattern‑fill scanline routine without any corresponding memory allocation, leading the rendering process to consume 100% CPU for an attacker‑controlled, extended duration. The weakness is an unchecked input error (CWE‑606).
Affected Systems
Red Hat Enterprise Linux 10, 6, 7, 8, 9, Red Hat Hardened Images and the Red Hummingbird package are affected. The vulnerability is present in the Poppler library distributed with these products.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of < 1% (0.00113) indicates a very low likelihood of exploitation, and the vulnerability is not listed in KEV. An attacker can supply a malicious PDF to any application that renders it via Poppler's Splash backend. The attack can be delivered locally or remotely, depending on how the application receives the PDF. The resulting denial of service is achieved by exhausting CPU resources without allocating memory, making the impact hard to mitigate by memory‑based protections.
OpenCVE Enrichment