Red Hat Product Errata RHSA-2026:25058 - Security Advisory Issued: 2026-06-10 Updated: 2026-06-10 RHSA-2026:25058 - Security Advisory Overview Updated Packages Synopsis Important: poppler security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for poppler is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince. Security Fix(es): poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication (CVE-2026-10118) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2460428 - CVE-2026-10118 poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication CVEs CVE-2026-10118 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM poppler-21.01.0-24.el9_8.1.src.rpm SHA-256: 4b2b2e242b3bf7ca7680e2811ce96a0a4594152ae78845a87cdac8b1d63e3731 x86_64 poppler-21.01.0-24.el9_8.1.i686.rpm SHA-256: e4d17ae2c996f674e67e7c286e40a97785bd3cd870b9ad1576528a130804da11 poppler-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: fe60d5626c73c8ccd617a53f6c350e646b0d4eaa1d049b1101f8fcdfb480f362 poppler-cpp-21.01.0-24.el9_8.1.i686.rpm SHA-256: 70670c53974d5eaf73494a473ac88384100a418758b5f4ef5ae961b6704988f3 poppler-cpp-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 418c00ef1e1b21ed1d5b3f5f4a503f161d5535d3185a7f967f1333072b819d4a poppler-cpp-debuginfo-21.01.0-24.el9_8.1.i686.rpm SHA-256: 82beb8251bd03bc71327d71e0873af11e7380bc4041c285b3692a955282afc44 poppler-cpp-debuginfo-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 768b558f3aa5d958b751d2b9c570053eee265ae7dcfca598175b400a758f024d poppler-debuginfo-21.01.0-24.el9_8.1.i686.rpm SHA-256: 9c965e21d6ec9da7f1a9bef2200a7be3209f467249e74af9c50b6a069c8e5d81 poppler-debuginfo-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 0b9d61450ae36762ebaf13162c6d78c0b8c357e0cc6f91af1c33c41fea25da45 poppler-debugsource-21.01.0-24.el9_8.1.i686.rpm SHA-256: a6f8579b1d1ceed4c0d9a81f93caf2006c65abd7cb881c30530a36f481b1d450 poppler-debugsource-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 79039e8e1804370387aca659ec21740c1c9c4900e8b00fb844e86db4cfefa2d5 poppler-glib-21.01.0-24.el9_8.1.i686.rpm SHA-256: a97f103c87b9a5257df2a36b9d60d0ff93efb3882561b1ceae2ddd74334cb86e poppler-glib-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 4b860e3815379a1779844e4a14c6b798e29b373c7b0b9e1cb5b73455d0000435 poppler-glib-debuginfo-21.01.0-24.el9_8.1.i686.rpm SHA-256: 396047c1c46f208c7b7a323967667100a5399db97bf293e9edccc6b66953074c poppler-glib-debuginfo-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 7216de8809f0c4262a7cca2f03e7794b1d0e57174b566ad4b0b1725769100a6b poppler-qt5-21.01.0-24.el9_8.1.i686.rpm SHA-256: 73f1918a29e5c30c8d2c5763b5bc5fa5351f48e4eee0bff9ed882b4d11006666 poppler-qt5-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 5418f7c57eec3d3dfac36acf5407e35179c79dac84b57290573ff4a8c2dc4dc0 poppler-qt5-debuginfo-21.01.0-24.el9_8.1.i686.rpm SHA-256: e6cdcb82e19da780ac9ed64e77ebd510a73d6d5f792da5a3cfb100b6ec261057 poppler-qt5-debuginfo-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: a9e36586d06d6d22dce077929c1df5c661f41a0e32c9c7ee449966a8bfbdc675 poppler-utils-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: e0e99ced800ced261959f7460580b04dd2dbec8240c005f2e1df84c6ecfef435 poppler-utils-debuginfo-21.01.0-24.el9_8.1.i686.rpm SHA-256: 4467d6289caa223fa91b1e692e17055781a432015ab792291711aaf7f500d06d poppler-utils-debuginfo-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: f78e9343ecec65a6ac9e97fc4cc6fc06e354a055efa924bd9f052c793124ac3f Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM poppler-21.01.0-24.el9_8.1.src.rpm SHA-256: 4b2b2e242b3bf7ca7680e2811ce96a0a4594152ae78845a87cdac8b1d63e3731 x86_64 poppler-21.01.0-24.el9_8.1.i686.rpm SHA-256: e4d17ae2c996f674e67e7c286e40a97785bd3cd870b9ad1576528a130804da11 poppler-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: fe60d5626c73c8ccd617a53f6c350e646b0d4eaa1d049b1101f8fcdfb480f362 poppler-cpp-21.01.0-24.el9_8.1.i686.rpm SHA-256: 70670c53974d5eaf73494a473ac88384100a418758b5f4ef5ae961b6704988f3 poppler-cpp-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 418c00ef1e1b21ed1d5b3f5f4a503f161d5535d3185a7f967f1333072b819d4a poppler-cpp-debuginfo-21.01.0-24.el9_8.1.i686.rpm SHA-256: 82beb8251bd03bc71327d71e0873af11e7380bc4041c285b3692a955282afc44 poppler-cpp-debuginfo-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 768b558f3aa5d958b751d2b9c570053eee265ae7dcfca598175b400a758f024d poppler-debuginfo-21.01.0-24.el9_8.1.i686.rpm SHA-256: 9c965e21d6ec9da7f1a9bef2200a7be3209f467249e74af9c50b6a069c8e5d81 poppler-debuginfo-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 0b9d61450ae36762ebaf13162c6d78c0b8c357e0cc6f91af1c33c41fea25da45 poppler-debugsource-21.01.0-24.el9_8.1.i686.rpm SHA-256: a6f8579b1d1ceed4c0d9a81f93caf2006c65abd7cb881c30530a36f481b1d450 poppler-debugsource-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 79039e8e1804370387aca659ec21740c1c9c4900e8b00fb844e86db4cfefa2d5 poppler-glib-21.01.0-24.el9_8.1.i686.rpm SHA-256: a97f103c87b9a5257df2a36b9d60d0ff93efb3882561b1ceae2ddd74334cb86e poppler-glib-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 4b860e3815379a1779844e4a14c6b798e29b373c7b0b9e1cb5b73455d0000435 poppler-glib-debuginfo-21.01.0-24.el9_8.1.i686.rpm SHA-256: 396047c1c46f208c7b7a323967667100a5399db97bf293e9edccc6b66953074c poppler-glib-debuginfo-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 7216de8809f0c4262a7cca2f03e7794b1d0e57174b566ad4b0b1725769100a6b poppler-qt5-21.01.0-24.el9_8.1.i686.rpm SHA-256: 73f1918a29e5c30c8d2c5763b5bc5fa5351f48e4eee0bff9ed882b4d11006666 poppler-qt5-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: 5418f7c57eec3d3dfac36acf5407e35179c79dac84b57290573ff4a8c2dc4dc0 poppler-qt5-debuginfo-21.01.0-24.el9_8.1.i686.rpm SHA-256: e6cdcb82e19da780ac9ed64e77ebd510a73d6d5f792da5a3cfb100b6ec261057 poppler-qt5-debuginfo-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: a9e36586d06d6d22dce077929c1df5c661f41a0e32c9c7ee449966a8bfbdc675 poppler-utils-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: e0e99ced800ced261959f7460580b04dd2dbec8240c005f2e1df84c6ecfef435 poppler-utils-debuginfo-21.01.0-24.el9_8.1.i686.rpm SHA-256: 4467d6289caa223fa91b1e692e17055781a432015ab792291711aaf7f500d06d poppler-utils-debuginfo-21.01.0-24.el9_8.1.x86_64.rpm SHA-256: f78e9343ecec65a6ac9e97fc4cc6fc06e354a055efa924bd9f052c793124ac3f Red Hat Enterprise Linux for IBM z Systems 9 SRPM poppler-21.01.0-24.el9_8.1.src.rpm SHA-256: 4b2b2e242b3bf7ca7680e2811ce96a0a4594152ae78845a87cdac8b1d63e3731 s390x poppler-21.01.0-24.el9_8.1.s390x.rpm SHA-256: 51afad6147ca0781f515dd3a1c0687220ea95f53d80324eef17d3c57c49bb930 poppler-cpp-21.01.0-24.el9_8.1.s390x.rpm SHA-256: dba8c7daad8a92317c8942b1686730abd78c1de322a0a73514b03021e9f35451 poppler-cpp-debuginfo-21.01.0-24.el9_8.1.s390x.rpm SHA-256: ee9eb03e5ce18634b3e832eb6c91004dbd519e5773c321378c0e7ab689de8f2c poppler-debuginfo-21.01.0-24.el9_8.1.s390x.rpm SHA-256: e82496dea99fd63f840680426dd5c7ac8cd2667b728c4678680dfb6b46b49f47 poppler-debugsource-21.01.0-24.el9_8.1.s390x.rpm SHA-256: 0a6135dab76362dd45f89455dad98bad1fa8523419ca3781adcfc1ef80b27379 poppler-glib-21.01.0-24.el9_8.1.s390x.rpm SHA-256: 984ba5d176a8924b95e9a576db6486b7cd38a241d4eaf8e2bd0a3246a4003a0c poppler-glib-debuginfo-21.01.0-24.el9_8.1.s390x.rpm SHA-256: db7c3db8deb0346e25eb9cfd7e41198ea8b69055f76f4e4cf98a83315ad2d66f poppler-qt5-21.01.0-24.el9_8.1.s390x.rpm SHA-256: 20e4ee3ce0386b2f03f3aa21154185fe6b05c02cb1c339bab3ae7bb35fe2099d poppler-qt5-debuginfo-21.01.0-24.el9_8.1.s
An integer overflow in the Poppler PDF rendering library (CVE-2026-10118, CVSS 7.8 HIGH) can lead to a heap buffer overflow when processing tiling patterns via unchecked dimension multiplication. This security update is rated Important and applies to Red Hat Enterprise Linux 9 across all supported architectures. Administrators should apply the provided Red Hat patch via their standard update channels to remediate affected systems.