CVE-2026-102620 Details
Description
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 245d3c6823377755f2c1d5fdddd010279c6ed94d. It is suggested to install a patch to address this issue.
A signed integer overflow vulnerability has been identified in Freedesktop Poppler versions 26.06.0, 26.07.0, and 26.08.0. The issue arises in the function 'FoFiTrueType::cvtSfnts' within 'fofi/FoFiTrueType.cc'. This vulnerability allows for local exploitation by manipulating TrueType fonts in a way that causes an integer overflow during PDF-to-PostScript conversion. The overflow leads to incorrect length and checksum calculations, resulting in corrupted PostScript output. The vulnerability has been publicly disclosed and exploited.
Users are advised to upgrade to a version of Poppler that includes the fix for this vulnerability. The fix has been committed but not yet released, so users should monitor for future Poppler releases that incorporate this patch.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/r1ck9-2q/cve_summit/blob/main/Signed-integer-overflow-in-FoFiTrueType-cvtSfnts-FoFiTrueType.cc-1210.md | [email protected] | ExploitTechnical Analysis |
| https://gitlab.freedesktop.org/poppler/poppler/-/commit/245d3c6823377755f2c1d5fdddd010279c6ed94d | [email protected] | Source CodeVendor |
| https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2326 | [email protected] | Issue TrackingVendor |
| https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1762 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-102620 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/942348 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411410 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411410/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-189 | Numeric Errors | [email protected] |
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Freedesktop Poppler | 26.07.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion