ELA-1792-1 poppler security update

multiple vulnerabilities

2026-08-04
Packagepoppler
Version0.48.0-2+deb9u8 (stretch), 0.71.0-5+deb10u5 (buster)
Related CVEs CVE-2025-43718 CVE-2025-43903 CVE-2025-50420 CVE-2025-52885 CVE-2025-52886 CVE-2026-10118


CVE-2025-43718

It was discovered that crafted PDF files containing deeply nested structures within the metadata could lead to Denial of Service. (This issue did not affect the poppler version found in Debian stretch.)

CVE-2025-43903

It was discovered signatures with non-empty encapsulated content (typically adbe.pkcs7.sha1) were not correctly verified, thereby allowing trivial signature forgery.

CVE-2025-50420

An infinite recursion issue was discovered in the pdfseparate(1) utility, which may cause denial of service via crafted PDF input file.

CVE-2025-52885

Antonio Morales discovered a use-after-free issue, which may lead to arbitrary code execution via crafted PDF input files. (This issue did not affect the poppler version found in Debian stretch.)

CVE-2025-52886

Kevin Backhouse discovered an integer overflow issue, which may lead to use-after-free via crafted PDF input file.

CVE-2026-10118

An integer overflow issue was discovered in tilingPatternFill(), which may lead to arbitrary code execution via crafted PDF input files.



For Debian 10 buster, these problems have been fixed in version 0.71.0-5+deb10u5.

For Debian 9 stretch, these problems have been fixed in version 0.48.0-2+deb9u8.

We recommend that you upgrade your poppler packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.