|
|
Log in / Subscribe / Register

Ubuntu alert USN-8400-1 (poppler)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8400-1] poppler vulnerability
Date:  Mon, 08 Jun 2026 14:04:03 +0000
Message-ID:  <E1wWaaB-0002Lj-Mc@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8400-1 June 08, 2026 poppler vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: poppler could be made to crash or run programs if it opened a specially crafted file. Software Description: - poppler: PDF rendering library Details: It was discovered that poppler incorrectly handled certain malformed PDF tiling patterns in the Splash backend. An attacker could possibly use this issue to execute arbitrary code, obtain sensitive information, or cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libpoppler156 26.01.0-2ubuntu0.1 poppler-utils 26.01.0-2ubuntu0.1 Ubuntu 25.10 libpoppler147 25.03.0-10ubuntu0.2 poppler-utils 25.03.0-10ubuntu0.2 Ubuntu 24.04 LTS libpoppler134 24.02.0-1ubuntu9.9 poppler-utils 24.02.0-1ubuntu9.9 Ubuntu 22.04 LTS libpoppler118 22.02.0-2ubuntu0.13 poppler-utils 22.02.0-2ubuntu0.13 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8400-1 CVE-2026-10118 Package Information: https://launchpad.net/ubuntu/+source/poppler/26.01.0-2ubu... https://launchpad.net/ubuntu/+source/poppler/25.03.0-10ub... https://launchpad.net/ubuntu/+source/poppler/24.02.0-1ubu... https://launchpad.net/ubuntu/+source/poppler/22.02.0-2ubu...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmomy7cACgkQcpJm3tlz hgEbwA/+Iu/xACvO+3TQdVTlvZgEJtGqQQDt6lZSVZ37hYD3eQv/sOdiaX6o/qcj TR/ZtwBklmZtA7OwG+NoOx9suhQTAmMe60avRMzR/v9Ec2nPFPRtCMoAzv17joRV BblPUEg4bfabuwPkyB49AqkL7g56jxy9WY3SGmiWHrFYwIs4v/xIX8zRhYju2kKW Hloil2HLdAWPvEcdRjbcNWpvU6wZ5NT64uPBLfcgWzRCtInAY/uxEFwrCBv2UiLf FE+nIQKk0nI6owKFv+OanjVUWpdZJfTtvZv92lZW3+KgUAPgAoxRlXTRxjmeZ8qs NnJmxxoaj3Zlfacv/kP32zhJaQ/Y0iVC14HUalft6PEdWJ3MMkXurR5vmPZJ4/AK RqJopW7SVLJ4ZvtrsGo/Si6Gs9PChkX4jAhrocrwoLoXiSCXZYH+bl2/VgeschW1 2F8NXoPkH3iArMDi4bSz7smUubH4w5/pBo56aV1gusPVjfoT82Wf5Eea0L5rl22G 8gK4X4spVksl6F8AflaaXhA5gWkgYegKk8MQdO5d2o0O7EEQ9R0G4ks7Qe9Aan9e k/sVj+P8RzxNoWSIhvutfaTeI28i3PLQA/2cp9z7dDw28VFAqHh+erDXgSXnvls2 YXH1/Emf0uKwmBbOEBruk11pk0UdGoKVK1Pk7tSNHVKxBczHoCY= =2deY -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds