CVE-2026-10118

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
Configurations

No configuration.

History

10 Jun 2026, 12:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:25058 -

10 Jun 2026, 10:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:24984 -
  • () https://access.redhat.com/errata/RHSA-2026:24985 -

01 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 17:16

Updated : 2026-06-10 12:16


NVD link : CVE-2026-10118

Mitre link : CVE-2026-10118

CVE.ORG link : CVE-2026-10118


JSON object : View

Products Affected

No product.

CWE
CWE-190

Integer Overflow or Wraparound