[ubuntu/resolute-security] poppler 26.01.0-2ubuntu0.2 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Oct 7 12:48:42 UTC 2026


poppler (26.01.0-2ubuntu0.2) resolute-security; urgency=medium

  * SECURITY UPDATE: overflow in FoFiTrueType::cvtSfnts
    - debian/patches/CVE-2026-102620.patch: Fix integer overflow in
      FoFiTrueType::cvtSfnts in fofi/FoFiTrueType.cc.
    - CVE-2026-102620
  * SECURITY UPDATE: overflow in SplashClip::clipToPath
    - debian/patches/CVE-2026-102621.patch: Fix integer overflow in
      SplashClip::clipToPath in splash/SplashClip.cc.
    - CVE-2026-102621
  * SECURITY UPDATE: null pointer deref issue
    - debian/patches/CVE-2026-93312.patch: Fix nullptr + number in
      poppler/JBIG2Stream.cc.
    - CVE-2026-93312
  * SECURITY UPDATE: overflow in JBIG2Stream::readCodeTableSeg
    - debian/patches/CVE-2026-93313.patch: Fix integer overflow in
      JBIG2Stream::readCodeTableSeg in poppler/JBIG2Stream.cc.
    - CVE-2026-93313
  * SECURITY UPDATE: overflow in FoFiTrueType::mapCodeToGID
    - debian/patches/CVE-2026-93314.patch: FoFiTrueType::mapCodeToGID: Improve
      b*12 overflow check in fofi/FoFiTrueType.cc.
    - CVE-2026-93314

Date: 2026-10-06 18:00:13.238051+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/poppler/26.01.0-2ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list