CVE-2026-10118
HIGHPoppler: integer overflow in poppler splashoutputdev::tilingpatternfill leads to heap buffer overflow via unchecked dimension multiplication
Title source: cnaDescription
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
References (21)
Core 21
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:24985
https://access.redhat.com/errata/RHSA-2026:24985
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:25058
https://access.redhat.com/errata/RHSA-2026:25058
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:24984
https://access.redhat.com/errata/RHSA-2026:24984
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:27720
https://access.redhat.com/errata/RHSA-2026:27720
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:27724
https://access.redhat.com/errata/RHSA-2026:27724
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:27725
https://access.redhat.com/errata/RHSA-2026:27725
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:27727
https://access.redhat.com/errata/RHSA-2026:27727
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:27721
https://access.redhat.com/errata/RHSA-2026:27721
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:27722
https://access.redhat.com/errata/RHSA-2026:27722
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:27723
https://access.redhat.com/errata/RHSA-2026:27723
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:29952
https://access.redhat.com/errata/RHSA-2026:29952
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:30044
https://access.redhat.com/errata/RHSA-2026:30044
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:30078
https://access.redhat.com/errata/RHSA-2026:30078
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:30088
https://access.redhat.com/errata/RHSA-2026:30088
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:30089
https://access.redhat.com/errata/RHSA-2026:30089
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:30134
https://access.redhat.com/errata/RHSA-2026:30134
Vdb Entry, X_Refsource_Redhat vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-10118
Issue Tracking, X_Refsource_Redhat issue-tracking
x_refsource_redhat
RHBZ#2460428
https://bugzilla.redhat.com/show_bug.cgi?id=2460428
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:30087
https://access.redhat.com/errata/RHSA-2026:30087
Scores
CVSS v3
7.8
EPSS
0.0025
EPSS Percentile
16.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-190
Status
published
Products (26)
Red Hat/Red Hat AI Inference Server 3.3
1782352847
Red Hat/Red Hat AI Inference Server 3.3
1782352919
Red Hat/Red Hat AI Inference Server 3.3
1782352950
Red Hat/Red Hat AI Inference Server 3.3
1782353093
Red Hat/Red Hat Enterprise Linux 10
Red Hat/Red Hat Enterprise Linux 10
0:24.02.0-7.el10_2.2
Red Hat/Red Hat Enterprise Linux 10.0 Extended Update Support
0:24.02.0-7.el10_0.1
Red Hat/Red Hat Enterprise Linux 6
Red Hat/Red Hat Enterprise Linux 7
Red Hat/Red Hat Enterprise Linux 7 Extended Lifecycle Support
0:0.22.5-7.el7_9
... and 16 more
Published
Jun 01, 2026
Tracked Since
Jun 01, 2026