High severity7.8NVD Advisory· Published Jun 1, 2026· Updated Jul 21, 2026
CVE-2026-10118
CVE-2026-10118
Description
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the tilingPatternFill function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13- osv-coords12 versionspkg:rpm/almalinux/popplerpkg:rpm/almalinux/poppler-cpppkg:rpm/almalinux/poppler-cpp-develpkg:rpm/almalinux/poppler-develpkg:rpm/almalinux/poppler-glibpkg:rpm/almalinux/poppler-glib-develpkg:rpm/almalinux/poppler-glib-docpkg:rpm/almalinux/poppler-qt5pkg:rpm/almalinux/poppler-qt5-develpkg:rpm/almalinux/poppler-qt6pkg:rpm/almalinux/poppler-qt6-develpkg:rpm/almalinux/poppler-utils
< 20.11.0-14.el8_10+ 11 more
- (no CPE)range: < 20.11.0-14.el8_10
- (no CPE)range: < 20.11.0-14.el8_10
- (no CPE)range: < 20.11.0-14.el8_10
- (no CPE)range: < 20.11.0-14.el8_10
- (no CPE)range: < 20.11.0-14.el8_10
- (no CPE)range: < 20.11.0-14.el8_10
- (no CPE)range: < 20.11.0-14.el8_10
- (no CPE)range: < 20.11.0-14.el8_10
- (no CPE)range: < 20.11.0-14.el8_10
- (no CPE)range: < 24.02.0-7.el10_2.2
- (no CPE)range: < 24.02.0-7.el10_2.2
- (no CPE)range: < 20.11.0-14.el8_10
Patches
Vulnerability mechanics
References
20- access.redhat.com/errata/RHSA-2026:24984nvd
- access.redhat.com/errata/RHSA-2026:24985nvd
- access.redhat.com/errata/RHSA-2026:25058nvd
- access.redhat.com/errata/RHSA-2026:27720nvd
- access.redhat.com/errata/RHSA-2026:27721nvd
- access.redhat.com/errata/RHSA-2026:27722nvd
- access.redhat.com/errata/RHSA-2026:27723nvd
- access.redhat.com/errata/RHSA-2026:27724nvd
- access.redhat.com/errata/RHSA-2026:27725nvd
- access.redhat.com/errata/RHSA-2026:27727nvd
- access.redhat.com/errata/RHSA-2026:29952nvd
- access.redhat.com/errata/RHSA-2026:30044nvd
- access.redhat.com/errata/RHSA-2026:30078nvd
- access.redhat.com/errata/RHSA-2026:30087nvd
- access.redhat.com/errata/RHSA-2026:30088nvd
- access.redhat.com/errata/RHSA-2026:30089nvd
- access.redhat.com/errata/RHSA-2026:30134nvd
- access.redhat.com/security/cve/CVE-2026-10118nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10118.jsonnvd
News mentions
0No linked articles in our index yet.