CVE-2026-93312 PUBLISHED

Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference

Assigner: VulDB
Reserved: 17.09.2026 Published: 18.09.2026 Updated: 18.09.2026

A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor Freedesktop
Product Poppler
Versions
  • Version 26.07.0 is affected
  • Version 26.08.0 is unaffected

Credits

  • r1ck99 (VulDB User) reporter

References

Problem Types

  • NULL Pointer Dereference CWE
  • Denial of Service CWE