CVE-2026-10118

HIGH

Poppler: integer overflow in poppler splashoutputdev::tilingpatternfill leads to heap buffer overflow via unchecked dimension multiplication

Title source: cna
STIX 2.1

Description

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

References (21)

Core 21
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:24985
https://access.redhat.com/errata/RHSA-2026:24985
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:25058
https://access.redhat.com/errata/RHSA-2026:25058
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:24984
https://access.redhat.com/errata/RHSA-2026:24984
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:27720
https://access.redhat.com/errata/RHSA-2026:27720
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:27724
https://access.redhat.com/errata/RHSA-2026:27724
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:27725
https://access.redhat.com/errata/RHSA-2026:27725
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:27727
https://access.redhat.com/errata/RHSA-2026:27727
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:27721
https://access.redhat.com/errata/RHSA-2026:27721
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:27722
https://access.redhat.com/errata/RHSA-2026:27722
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:27723
https://access.redhat.com/errata/RHSA-2026:27723
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:29952
https://access.redhat.com/errata/RHSA-2026:29952
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:30044
https://access.redhat.com/errata/RHSA-2026:30044
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:30078
https://access.redhat.com/errata/RHSA-2026:30078
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:30088
https://access.redhat.com/errata/RHSA-2026:30088
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:30089
https://access.redhat.com/errata/RHSA-2026:30089
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:30134
https://access.redhat.com/errata/RHSA-2026:30134
Vdb Entry, X_Refsource_Redhat vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-10118
Issue Tracking, X_Refsource_Redhat issue-tracking x_refsource_redhat
RHBZ#2460428
https://bugzilla.redhat.com/show_bug.cgi?id=2460428
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:30087
https://access.redhat.com/errata/RHSA-2026:30087

Scores

CVSS v3 7.8
EPSS 0.0025
EPSS Percentile 16.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-190
Status published
Products (26)
Red Hat/Red Hat AI Inference Server 3.3 1782352847
Red Hat/Red Hat AI Inference Server 3.3 1782352919
Red Hat/Red Hat AI Inference Server 3.3 1782352950
Red Hat/Red Hat AI Inference Server 3.3 1782353093
Red Hat/Red Hat Enterprise Linux 10
Red Hat/Red Hat Enterprise Linux 10 0:24.02.0-7.el10_2.2
Red Hat/Red Hat Enterprise Linux 10.0 Extended Update Support 0:24.02.0-7.el10_0.1
Red Hat/Red Hat Enterprise Linux 6
Red Hat/Red Hat Enterprise Linux 7
Red Hat/Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:0.22.5-7.el7_9
... and 16 more
Published Jun 01, 2026
Tracked Since Jun 01, 2026