Debian alert DLA-4709-1 (poppler)
| From: | Guilhem Moulin <guilhem@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4709-1] poppler security update | |
| Date: | Sat, 01 Aug 2026 00:14:41 +0200 | |
| Message-ID: | <am0eUZNg6yER_wcN@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4709-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin July 31, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : poppler Version : 20.09.0-3.1+deb11u3 22.12.0-2+deb12u3 CVE ID : CVE-2025-43718 CVE-2025-43903 CVE-2025-50420 CVE-2025-52885 CVE-2025-52886 CVE-2026-10118 Debian Bug : 1103545 1108784 1110463 1117046 1117853 1138708 Multiple vulnerabilities were discovered in poppler, a PDF rendering library, which could result in signature forgery, information disclosure, denial of service, or potentially the execution of arbitrary code. The following security issues have been identified (and fixed) in poppler as shipped in Debian bullseye and Debian bookworm. CVE-2025-43903 It was discovered signatures with non-empty encapsulated content (typically adbe.pkcs7.sha1) were not correctly verified, thereby allowing trivial signature forgery. CVE-2025-50420 An infinite recursion issue was discovered in the pdfseparate(1) utility, which may cause denial of service via crafted PDF input file. CVE-2025-52886 Kevin Backhouse discovered an integer overflow issue, which may lead to use-after-free via crafted PDF input file. For Debian 12 bookworm, these problems have been fixed in version 22.12.0-2+deb12u3. In addition, the following issues have been fixed in the poppler version as shipped in Debian bullseye (for bookworm, these issues were already fixed in 22.12.0-2+deb12u2 from DSA-6334-1): CVE-2025-43718 It was discovered that crafted PDF files containing deeply nested structures within the metadata could lead to Denial of Service. CVE-2025-52885 Antonio Morales discovered a use-after-free issue, which may lead to arbitrary code execution via crafted PDF input files. CVE-2026-10118 An integer overflow issue was discovered in tilingPatternFill, which may lead to arbitrary code execution via crafted PDF input files. For Debian 11 bullseye, these problems have been fixed in version 20.09.0-3.1+deb11u3. We recommend that you upgrade your poppler packages. For the detailed security status of poppler please refer to its security tracker page at: https://security-tracker.debian.org/tracker/poppler Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmptHlEACgkQ05pJnDwh pVIDfw//ZyTRotPJ5Adyge3UorVQufBE3twLAGdTJDZqnNuMI/ZjvU4Sw7V8dfeZ WYYFv3Kky9F45qU3IQViSaROjPnKLXcQEhobwuHnAKY6ojH/4339OstgeNelEjzn 46agnikae5mcqP/nArNFNY02XOTzSUemlsflmcb5kvKT639JhnDXYl7nsMjm7ygq yaRYd10SN5m/zGD18aJoenfELOvKM8aFLuP33njaimsC1gS4CC0V/fe94HtxEbdq gNwhPMZTT+N8pOpeNKzCgKQngDN7dX84ojiOOPZBKiQ2qLo+2XUA80qS9VI+plUb h8v88ozPqfam6CnzO/uYpiP84orB32uRNiozbMe5qrCk+xjebpP2xT1Mwjm/0zys iaq1Cl4e9UVDfJjgtttdJ6CFOAZv6yugQjYAFvPYR3sXBZ47oWe6ss/F188HMeYA 0p4vdfHiACMQMUnwOYtiXJDYIYueWryS/p+YqaYsUbIdwDQQFdgp9BSC1nuiSdp5 ysLntXfnosVKyALZYASqpzb7KCxltw4BiIic/9qkLIffaYFNnJrIJ/VSpnt5lusp 7U5TOQ9PGs2W6EoBnXHpUivoE3iMEU8gS+bzMWxFAI3ku65/IaKU/yDhEhjj08UU 7skab9ja4JvS/XzcoF7nAI8ouCSELyHur+QQuRq5qqNhCsQkFTk= =6oZ+ -----END PGP SIGNATURE-----
