Integer Overflow in Freedesktop Poppler Affects Local Security Features
CVE-2026-102620
Key Information:
- Vendor
Freedesktop
- Status
- Vendor
- CVE Published:
- 29 September 2026
Badges
What is CVE-2026-102620?
A critical vulnerability has been identified in Freedesktop Poppler versions 26.06.0, 26.07.0, and 26.08.0, stemming from an integer overflow in the FoFiTrueType::cvtSfnts function located in fofi/FoFiTrueType.cc. This flaw enables local attackers to potentially execute malicious code. The vulnerability has been publicly disclosed, and it is advisable for users to apply the available patch (commit: 245d3c6823377755f2c1d5fdddd010279c6ed94d) to mitigate risks associated with this exploit.
Affected Version(s)
Poppler 26.06.0
Poppler 26.07.0
Poppler 26.08.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
