PT-2026-95195 · Freedesktop · Poppler

·

CVE-2026-93312

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Freedesktop Poppler version 26.07.0
Description A remote flaw exists in the JBIG2Stream::rewind() function within the poppler/JBIG2Stream.cc file. This issue leads to a null pointer dereference, which occurs when the software attempts to read from a memory address that is null, typically resulting in a program crash.
Recommendations Update to version 26.08.0.

Exploit

Fix

NULL Pointer Dereference

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93312
ECHO-16F1-C40A-5BF3

Affected Products

Poppler