Red Hat Product Errata RHSA-2026:27727 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:27727 - Security Advisory Overview Updated Packages Synopsis Important: poppler security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for poppler is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince. Security Fix(es): poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication (CVE-2026-10118) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2460428 - CVE-2026-10118 poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication CVEs CVE-2026-10118 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 SRPM poppler-20.11.0-2.el8_4.3.src.rpm SHA-256: db924e335fb2c1c2e5f623ce17aa8bda3c283a89a6805c9c867e5fae063ca18f x86_64 poppler-20.11.0-2.el8_4.3.i686.rpm SHA-256: 4cc6fef771dd75d5188c798cc4ff421d8b60aca2ec814d28111bf3cff0d04935 poppler-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 148ad7b4f5396b97d5b2ffecf06f793f061cf35f4c9f3bf6e230d8394bd7b19d poppler-cpp-debuginfo-20.11.0-2.el8_4.3.i686.rpm SHA-256: 69f91a7a8c3baa25f328347e31c37f2191efe053af63ae4456e2a70ffcd1ff8a poppler-cpp-debuginfo-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 770f0d7237e40a23f6b018095455454da51e183d4b907108bd84543fdfed8037 poppler-debuginfo-20.11.0-2.el8_4.3.i686.rpm SHA-256: cd3ba7398c81ea9e85ee8ca78d39393bc2051d607a66ac4e7445af96b613ad46 poppler-debuginfo-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 8de69483f5ce167af73ff073ccc2a03d8078106d6e9a1e8faeba7a74fe49a61b poppler-debugsource-20.11.0-2.el8_4.3.i686.rpm SHA-256: b0982e56de749114b33f545ecec1980bea829eefc9ec6abe510d8c81729be53d poppler-debugsource-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 568fbaf799f4a595ac0dea8160817c555f06bb4e79487b390226e7c31a0cdcd1 poppler-glib-20.11.0-2.el8_4.3.i686.rpm SHA-256: 694bff8861107e3f799c411a6e9e0767b2d38c3e3863d0b2dbdd929133eeda87 poppler-glib-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 33a11fd8c76fd8ba2a0d92fa86be7032aeec4cfda60f3f1d8b684081bf37a855 poppler-glib-debuginfo-20.11.0-2.el8_4.3.i686.rpm SHA-256: 92a8a9d753027dd1bc5ee75445d2fb48d5f67ad05ee57f369e5d2a6e989b3cdf poppler-glib-debuginfo-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: ab2b5e75123a182aad1c6078b5ab7307ff109a61e33734f5a20c1f2c5fac1e92 poppler-qt5-debuginfo-20.11.0-2.el8_4.3.i686.rpm SHA-256: 74d1f2f164ec40dac9163c8e38e3c12280ee41f50e5ee7f47dbf673cbac6094e poppler-qt5-debuginfo-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: f365f5ef52108397fa9081606ddb3fd34d91fa44619bc535b3128e68a45261cb poppler-utils-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 2463f47858e972af17df55d575d247a496532b08e2a62275bd7e6cdd077f98c3 poppler-utils-debuginfo-20.11.0-2.el8_4.3.i686.rpm SHA-256: d517544df38e1bcb438e5a01eef3d281547edad9ce2c771627879c62bea1c613 poppler-utils-debuginfo-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 7dea7501b9f97b5a27c0ef32e46d05c939b501380eb1c755c0c9b4d675f80ed6 Red Hat Enterprise Linux Server - AUS 8.4 SRPM poppler-20.11.0-2.el8_4.3.src.rpm SHA-256: db924e335fb2c1c2e5f623ce17aa8bda3c283a89a6805c9c867e5fae063ca18f x86_64 poppler-20.11.0-2.el8_4.3.i686.rpm SHA-256: 4cc6fef771dd75d5188c798cc4ff421d8b60aca2ec814d28111bf3cff0d04935 poppler-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 148ad7b4f5396b97d5b2ffecf06f793f061cf35f4c9f3bf6e230d8394bd7b19d poppler-cpp-debuginfo-20.11.0-2.el8_4.3.i686.rpm SHA-256: 69f91a7a8c3baa25f328347e31c37f2191efe053af63ae4456e2a70ffcd1ff8a poppler-cpp-debuginfo-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 770f0d7237e40a23f6b018095455454da51e183d4b907108bd84543fdfed8037 poppler-debuginfo-20.11.0-2.el8_4.3.i686.rpm SHA-256: cd3ba7398c81ea9e85ee8ca78d39393bc2051d607a66ac4e7445af96b613ad46 poppler-debuginfo-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 8de69483f5ce167af73ff073ccc2a03d8078106d6e9a1e8faeba7a74fe49a61b poppler-debugsource-20.11.0-2.el8_4.3.i686.rpm SHA-256: b0982e56de749114b33f545ecec1980bea829eefc9ec6abe510d8c81729be53d poppler-debugsource-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 568fbaf799f4a595ac0dea8160817c555f06bb4e79487b390226e7c31a0cdcd1 poppler-glib-20.11.0-2.el8_4.3.i686.rpm SHA-256: 694bff8861107e3f799c411a6e9e0767b2d38c3e3863d0b2dbdd929133eeda87 poppler-glib-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 33a11fd8c76fd8ba2a0d92fa86be7032aeec4cfda60f3f1d8b684081bf37a855 poppler-glib-debuginfo-20.11.0-2.el8_4.3.i686.rpm SHA-256: 92a8a9d753027dd1bc5ee75445d2fb48d5f67ad05ee57f369e5d2a6e989b3cdf poppler-glib-debuginfo-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: ab2b5e75123a182aad1c6078b5ab7307ff109a61e33734f5a20c1f2c5fac1e92 poppler-qt5-debuginfo-20.11.0-2.el8_4.3.i686.rpm SHA-256: 74d1f2f164ec40dac9163c8e38e3c12280ee41f50e5ee7f47dbf673cbac6094e poppler-qt5-debuginfo-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: f365f5ef52108397fa9081606ddb3fd34d91fa44619bc535b3128e68a45261cb poppler-utils-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 2463f47858e972af17df55d575d247a496532b08e2a62275bd7e6cdd077f98c3 poppler-utils-debuginfo-20.11.0-2.el8_4.3.i686.rpm SHA-256: d517544df38e1bcb438e5a01eef3d281547edad9ce2c771627879c62bea1c613 poppler-utils-debuginfo-20.11.0-2.el8_4.3.x86_64.rpm SHA-256: 7dea7501b9f97b5a27c0ef32e46d05c939b501380eb1c755c0c9b4d675f80ed6 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
An integer overflow in Poppler's `SplashOutputDev::tilingPatternFill` function (CVE-2026-10118) can lead to a heap buffer overflow when processing specially crafted PDF files. The Red Hat advisory rates this as an Important security impact, though a specific CVSS score is not provided in the excerpt. The update addresses the vulnerability for Red Hat Enterprise Linux 8.4 Extended Update Support, with fixed packages including `poppler-20.11.0-2.el8_4.3`.