Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised. | |
| Title | Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference | |
| First Time appeared |
Freedesktop
Freedesktop poppler |
|
| Weaknesses | CWE-404 CWE-476 |
|
| CPEs | cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freedesktop
Freedesktop poppler |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-18T00:45:12.489Z
Reserved: 2026-09-17T17:13:08.412Z
Link: CVE-2026-93312
No data.
Status : Received
Published: 2026-09-18T01:16:56.710
Modified: 2026-09-18T01:16:56.710
Link: CVE-2026-93312
No data.
OpenCVE Enrichment
No data.