CVE-2026-102621 Details
Description
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading to version 26.09.0 is able to address this issue. The name of the patch is 323c91036d99926a8b90dc14329f7b40aece22f8. It is recommended to upgrade the affected component.
A signed integer overflow vulnerability has been identified in Freedesktop Poppler versions prior to 26.08.0. The issue arises in the SplashClip::clipToPath function within SplashClip.cc, where the 'count' variable, derived from untrusted PDF path data, is multiplied by four without adequate bounds checking. This manipulation can lead to a heap buffer overflow, memory corruption, and potentially arbitrary code execution, depending on the heap layout. The vulnerability can be exploited locally, and a public exploit is available.
Users are advised to upgrade to Poppler version 26.09.0, where this vulnerability has been fixed. The specific commit that addresses the issue is 323c91036d99926a8b90dc14329f7b40aece22f8.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/r1ck9-2q/cve_summit/blob/main/Signed-integer-overflow-in-SplashClip-clipToPath-SplashClip.cc-214.md | [email protected] | ExploitTechnical Analysis |
| https://gitlab.freedesktop.org/poppler/poppler/-/commit/323c91036d99926a8b90dc14329f7b40aece22f8 | [email protected] | Source CodeVendor |
| https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2325 | [email protected] | Issue TrackingVendor |
| https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1763 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-102621 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/942349 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411411 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411411/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-189 | Numeric Errors | [email protected] |
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Freedesktop Poppler | 26.07.0 (semver) 26.08.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion