Red Hat Product Errata RHSA-2026:24985 - Security Advisory Issued: 2026-06-10 Updated: 2026-06-10 RHSA-2026:24985 - Security Advisory Overview Updated Packages Synopsis Important: poppler security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for poppler is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince. Security Fix(es): poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication (CVE-2026-10118) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2460428 - CVE-2026-10118 poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication CVEs CVE-2026-10118 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM poppler-24.02.0-7.el10_2.2.src.rpm SHA-256: 457f24419633f77a0fe01f9a1fffd6595acd70ee4993edb2a5f49f27265ec12e x86_64 poppler-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: ea5fc3e99ce334b4d467a9084ab4e6029305a19cb2ce0b83af06721242ce7adf poppler-cpp-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: c9625f1cd8278650bc0a6ee9a70a72e752ab3e9f8542d06b98cff4932518d179 poppler-cpp-debuginfo-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: bb036dbe064bdc55ecd866fd92ed9bb66fb9eb874a9b54fed39de36f5fbad72c poppler-debuginfo-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: c5786ef7ac02b8f9ceedbad9f265903997ee298770237b53370a80cad903e8f4 poppler-debugsource-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: 371f732fa6fae61175ce619fbb4309e6a3253a96a49684bd48948b7f26de734e poppler-glib-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: b3b1ecc0df4bc7d1564395ed9959acfd5871528701cdaba064c6aa3dcef982df poppler-glib-debuginfo-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: dcc5533779b6ac31c42a8f52c39067d7fde513b97e320613ecbea3e33cbfc234 poppler-qt6-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: ec31c266db9bc1a47ef24d5f646dbd6eb38d586ccee2157a730123ee95650916 poppler-qt6-debuginfo-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: 80f56a44c6621473213a06824e7cf4c315f7850d2acf5cb8e29d890c8f21d944 poppler-utils-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: 58aae936f3e54226fc9bdbab5b1aa27ad700a6ff04d4b0b1e15d7445bcb5e80d poppler-utils-debuginfo-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: c54ef34b60d8e31278dbe4c3c99c5cfaad2aefd9a2a8d82e518584071b6d064f Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM poppler-24.02.0-7.el10_2.2.src.rpm SHA-256: 457f24419633f77a0fe01f9a1fffd6595acd70ee4993edb2a5f49f27265ec12e x86_64 poppler-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: ea5fc3e99ce334b4d467a9084ab4e6029305a19cb2ce0b83af06721242ce7adf poppler-cpp-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: c9625f1cd8278650bc0a6ee9a70a72e752ab3e9f8542d06b98cff4932518d179 poppler-cpp-debuginfo-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: bb036dbe064bdc55ecd866fd92ed9bb66fb9eb874a9b54fed39de36f5fbad72c poppler-debuginfo-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: c5786ef7ac02b8f9ceedbad9f265903997ee298770237b53370a80cad903e8f4 poppler-debugsource-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: 371f732fa6fae61175ce619fbb4309e6a3253a96a49684bd48948b7f26de734e poppler-glib-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: b3b1ecc0df4bc7d1564395ed9959acfd5871528701cdaba064c6aa3dcef982df poppler-glib-debuginfo-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: dcc5533779b6ac31c42a8f52c39067d7fde513b97e320613ecbea3e33cbfc234 poppler-qt6-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: ec31c266db9bc1a47ef24d5f646dbd6eb38d586ccee2157a730123ee95650916 poppler-qt6-debuginfo-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: 80f56a44c6621473213a06824e7cf4c315f7850d2acf5cb8e29d890c8f21d944 poppler-utils-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: 58aae936f3e54226fc9bdbab5b1aa27ad700a6ff04d4b0b1e15d7445bcb5e80d poppler-utils-debuginfo-24.02.0-7.el10_2.2.x86_64.rpm SHA-256: c54ef34b60d8e31278dbe4c3c99c5cfaad2aefd9a2a8d82e518584071b6d064f Red Hat Enterprise Linux for IBM z Systems 10 SRPM poppler-24.02.0-7.el10_2.2.src.rpm SHA-256: 457f24419633f77a0fe01f9a1fffd6595acd70ee4993edb2a5f49f27265ec12e s390x poppler-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 6f29aba167e3708f44564502b610adb580a64e130c8383a02265eb90d3030d0b poppler-cpp-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 042a3252b7f507c22caafefdcd0aad9d94862c781e8b7b7a431c53b7eec039b4 poppler-cpp-debuginfo-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 0be205809b5598aa870e7983698f4ee88520d2444b4680078c10667fa0d4b2de poppler-debuginfo-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 7ea08573bd90da5ad236911f9adb571f6c24145474ebb5b56388a7df4a366469 poppler-debugsource-24.02.0-7.el10_2.2.s390x.rpm SHA-256: adca1a3b639fddc5dd2f04a77b3416483d060bdec766ea77bca866f44ff344fa poppler-glib-24.02.0-7.el10_2.2.s390x.rpm SHA-256: e93bd401d4addeca728de1b8273392e1f63cbc8c28290a2af1d2f843deb11d2e poppler-glib-debuginfo-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 5bfcdb7ce31f50e13afe9b22e8ad1f4fcdd333a6cae202b71d6431278462cc98 poppler-qt6-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 52fb487f9b43ddbf70c71d52b17f8e31c37bead5b195dc9acd4aeaf2ed4bfb06 poppler-qt6-debuginfo-24.02.0-7.el10_2.2.s390x.rpm SHA-256: c16b464b9f66223c5063584811c382d202fa402efc08235e285f8cb5f8d6e436 poppler-utils-24.02.0-7.el10_2.2.s390x.rpm SHA-256: b0d3158f6c70bffd1d7ff5bab2edc7199ffe2df40d48d1ab9db796d520572c0d poppler-utils-debuginfo-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 416ee9147e9b9e6117de9077fdebb2aa32528c8f2b360e37e7ec44a3f81ea385 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM poppler-24.02.0-7.el10_2.2.src.rpm SHA-256: 457f24419633f77a0fe01f9a1fffd6595acd70ee4993edb2a5f49f27265ec12e s390x poppler-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 6f29aba167e3708f44564502b610adb580a64e130c8383a02265eb90d3030d0b poppler-cpp-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 042a3252b7f507c22caafefdcd0aad9d94862c781e8b7b7a431c53b7eec039b4 poppler-cpp-debuginfo-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 0be205809b5598aa870e7983698f4ee88520d2444b4680078c10667fa0d4b2de poppler-debuginfo-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 7ea08573bd90da5ad236911f9adb571f6c24145474ebb5b56388a7df4a366469 poppler-debugsource-24.02.0-7.el10_2.2.s390x.rpm SHA-256: adca1a3b639fddc5dd2f04a77b3416483d060bdec766ea77bca866f44ff344fa poppler-glib-24.02.0-7.el10_2.2.s390x.rpm SHA-256: e93bd401d4addeca728de1b8273392e1f63cbc8c28290a2af1d2f843deb11d2e poppler-glib-debuginfo-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 5bfcdb7ce31f50e13afe9b22e8ad1f4fcdd333a6cae202b71d6431278462cc98 poppler-qt6-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 52fb487f9b43ddbf70c71d52b17f8e31c37bead5b195dc9acd4aeaf2ed4bfb06 poppler-qt6-debuginfo-24.02.0-7.el10_2.2.s390x.rpm SHA-256: c16b464b9f66223c5063584811c382d202fa402efc08235e285f8cb5f8d6e436 poppler-utils-24.02.0-7.el10_2.2.s390x.rpm SHA-256: b0d3158f6c70bffd1d7ff5bab2edc7199ffe2df40d48d1ab9db796d520572c0d poppler-utils-debuginfo-24.02.0-7.el10_2.2.s390x.rpm SHA-256: 416ee9147e9b9e6117de9077fdebb2aa32528c8f2b360e37e7ec44a3f81ea385 Red Hat Enterprise Linux for Power, little endian 10 SRPM poppler-24.02.0-7.el10_2.2.src.rpm SHA-256: 457f24419633f77a0fe01f9a1fffd6595acd70ee4993edb2a5f49f27265ec12e ppc64le poppler-24.02.0-7.el10_2.2.ppc64le.rpm SHA-256: ea0b3b985546eb6da9cd7738eda90b3e6aa373ad95f018fd85d95f33ca6ebc96 poppler-cpp-24.02.0-7.el10_2.2.ppc64le.rpm SHA-256: 5a040d78a53d98d48e33edaace2153f1e32069ea65f909dc8ac498a04869fe24 poppler-cpp-debuginfo-24.02.0-7.el10_2.2.ppc64le.rpm SHA-256: 45a949ab1f3256f0137a254ec2d503d8374dbac3141bb51b5046dc7fc05c67dc poppler-deb
A heap buffer overflow vulnerability (CVE-2026-10118, CVSS 7.8 HIGH) exists in the poppler PDF rendering library due to an integer overflow in the `SplashOutputDev::tilingPatternFill` function caused by unchecked dimension multiplication. The article does not specify the affected or fixed version ranges for poppler. Red Hat has released an update rated Important for Red Hat Enterprise Linux 10 to address this issue.