Security News

Cybersecurity news aggregator

🐧
HIGH Updates Red Hat Errata

RHSA-2026:33169: Important: evince security update

This vulnerability (CVE-2026-46529) in the Evince document viewer is an argument injection flaw in the handling of PDF `/GoToR` actions, which enables single-click remote code execution via the `--gtk-module` dlopen mechanism. The Red Hat advisory rates the impact as Important, but the article does not provide a specific CVSS score or the precise affected and fixed version numbers for the evince package. The update is available for Red Hat Enterprise Linux 9.6 Extended Update Support and related variants, and administrators should apply the referenced security update to remediate.
Read Full Article →

Red Hat Product Errata RHSA-2026:33169 - Security Advisory Issued: 2026-06-29 Updated: 2026-06-29 RHSA-2026:33169 - Security Advisory Overview Updated Packages Synopsis Important: evince security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for evince is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The evince packages provide a simple multi-page document viewer for Portable Document Format (PDF), PostScript (PS), Encapsulated PostScript (EPS) files, and, with additional back-ends, also the Device Independent File format (DVI) files. Security Fix(es): atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen (CVE-2026-46529) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2487669 - CVE-2026-46529 atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen CVEs CVE-2026-46529 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM evince-40.5-2.el9_6.1.src.rpm SHA-256: fcc6ec69392d44dcaf55b50bd9a413e314dc3496441499234b6c97f97ddc184f x86_64 evince-40.5-2.el9_6.1.x86_64.rpm SHA-256: 9454153fa03823716a9e2cae0118ff185bf416af149cca6284bb5858318eb4d2 evince-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 018cb44591fa355ddadd002108aa96d92a00e5fb18250cb121c5cd11612fcfa6 evince-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: e4acb0bb19bb9775e780467f3504c7ea842e86299de1d07a40deb8b2e9fd96fc evince-debugsource-40.5-2.el9_6.1.i686.rpm SHA-256: d675e4b3fc3b3bc0083c7575db9f93f011a954bc5422c01b3b2c3d45e503e087 evince-debugsource-40.5-2.el9_6.1.x86_64.rpm SHA-256: ed79e08d46fbab1c37d0e0aca2b75dc6dc2e68c589f80f4cd14e1a430d143d08 evince-dvi-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 67a2ae134c15870da49a6164b279501b16774868e970b1f965c6af86c0f4bc6e evince-dvi-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: 47eee6d6aa47721a25a8c9b2124157bb7209f5dc0fab4e59207220e8408caa61 evince-libs-40.5-2.el9_6.1.i686.rpm SHA-256: 73ddde296c1b56b1105df5fba898341cbb51a67873f03c0bf8b3f23f07f65510 evince-libs-40.5-2.el9_6.1.x86_64.rpm SHA-256: 1668bfe3da3355da7a83251de01c162791770367f15001f44f2221471b541b49 evince-libs-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 8ceece87770a80a883f2aae0fc4a0e3bf6320013bdb4779b84f51826ecbe56ed evince-libs-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: 42a53846c9ae87bc8e085d39d193345d5c8c667bfce6524dc6cdbfcfb960a8f5 evince-nautilus-40.5-2.el9_6.1.x86_64.rpm SHA-256: aa0eb2b78574f3e3ee920a61b2829357fa0330cf4747ee085525d07f85c4106f evince-nautilus-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 78e970b45eeeeddaa42500c6a89c3873acde4905b0117f5c3b928673a5db6d27 evince-nautilus-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: 11e810c01cec92f45df52b7aac03ead1c2f1beb44463b57871d16e2ce9a57e99 evince-previewer-40.5-2.el9_6.1.x86_64.rpm SHA-256: aaf1893c2954e079b74be1d9742d4880f3e35ca2f4347a69c3283731568b1b13 evince-previewer-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 64a2de479a6d7a40af63eb8608e2f52a53df481ee7851163dc1024aa2c8ff9ac evince-previewer-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: 30bb371c45926e1a14693a5f3e201c117deb400d34b410a9ab5f52ec6f26e64b evince-thumbnailer-40.5-2.el9_6.1.x86_64.rpm SHA-256: 5ad2280d2c91f44287e68ff040332d6246aa0776e76015a1381396974caafe4d evince-thumbnailer-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 16f59b9291f7265c128d9c7e550dd7a63deed6003c47a0a83d99f3955d8ee20c evince-thumbnailer-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: 18eedb17fa9d032fde30cc97d46731cd514feae5da849d9cd0a765125e1eb97d Red Hat Enterprise Linux Server - AUS 9.6 SRPM evince-40.5-2.el9_6.1.src.rpm SHA-256: fcc6ec69392d44dcaf55b50bd9a413e314dc3496441499234b6c97f97ddc184f x86_64 evince-40.5-2.el9_6.1.x86_64.rpm SHA-256: 9454153fa03823716a9e2cae0118ff185bf416af149cca6284bb5858318eb4d2 evince-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 018cb44591fa355ddadd002108aa96d92a00e5fb18250cb121c5cd11612fcfa6 evince-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: e4acb0bb19bb9775e780467f3504c7ea842e86299de1d07a40deb8b2e9fd96fc evince-debugsource-40.5-2.el9_6.1.i686.rpm SHA-256: d675e4b3fc3b3bc0083c7575db9f93f011a954bc5422c01b3b2c3d45e503e087 evince-debugsource-40.5-2.el9_6.1.x86_64.rpm SHA-256: ed79e08d46fbab1c37d0e0aca2b75dc6dc2e68c589f80f4cd14e1a430d143d08 evince-dvi-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 67a2ae134c15870da49a6164b279501b16774868e970b1f965c6af86c0f4bc6e evince-dvi-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: 47eee6d6aa47721a25a8c9b2124157bb7209f5dc0fab4e59207220e8408caa61 evince-libs-40.5-2.el9_6.1.i686.rpm SHA-256: 73ddde296c1b56b1105df5fba898341cbb51a67873f03c0bf8b3f23f07f65510 evince-libs-40.5-2.el9_6.1.x86_64.rpm SHA-256: 1668bfe3da3355da7a83251de01c162791770367f15001f44f2221471b541b49 evince-libs-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 8ceece87770a80a883f2aae0fc4a0e3bf6320013bdb4779b84f51826ecbe56ed evince-libs-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: 42a53846c9ae87bc8e085d39d193345d5c8c667bfce6524dc6cdbfcfb960a8f5 evince-nautilus-40.5-2.el9_6.1.x86_64.rpm SHA-256: aa0eb2b78574f3e3ee920a61b2829357fa0330cf4747ee085525d07f85c4106f evince-nautilus-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 78e970b45eeeeddaa42500c6a89c3873acde4905b0117f5c3b928673a5db6d27 evince-nautilus-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: 11e810c01cec92f45df52b7aac03ead1c2f1beb44463b57871d16e2ce9a57e99 evince-previewer-40.5-2.el9_6.1.x86_64.rpm SHA-256: aaf1893c2954e079b74be1d9742d4880f3e35ca2f4347a69c3283731568b1b13 evince-previewer-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 64a2de479a6d7a40af63eb8608e2f52a53df481ee7851163dc1024aa2c8ff9ac evince-previewer-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: 30bb371c45926e1a14693a5f3e201c117deb400d34b410a9ab5f52ec6f26e64b evince-thumbnailer-40.5-2.el9_6.1.x86_64.rpm SHA-256: 5ad2280d2c91f44287e68ff040332d6246aa0776e76015a1381396974caafe4d evince-thumbnailer-debuginfo-40.5-2.el9_6.1.i686.rpm SHA-256: 16f59b9291f7265c128d9c7e550dd7a63deed6003c47a0a83d99f3955d8ee20c evince-thumbnailer-debuginfo-40.5-2.el9_6.1.x86_64.rpm SHA-256: 18eedb17fa9d032fde30cc97d46731cd514feae5da849d9cd0a765125e1eb97d Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM evince-40.5-2.el9_6.1.src.rpm SHA-256: fcc6ec69392d44dcaf55b50bd9a413e314dc3496441499234b6c97f97ddc184f s390x evince-40.5-2.el9_6.1.s390x.rpm SHA-256: eed4805322972c7b6c05243ee135cce6f7dd9e39f204f70cb22d834dbd2bdf22 evince-debuginfo-40.5-2.el9_6.1.s390x.rpm SHA-256: 7d2145da09ed6ff9805ebbf63ddb10a5405019a5842699840686a024e798eb3c evince-debugsource-40.5-2.el9_6.1.s390x.rpm SHA-256: 62eac2805bd47b0c4b4bf9c463e43085210d02a0bfb51d8844361a214b98a32f evince-dvi-debuginfo-40.5-2.el9_6.1.s390x.rpm SHA-256: 52f6494a8559453520ebe87cbff6538c0bb75ee339062899c139526a6f5e4c45 evince-libs-40.5-2.el9_6.1.s390x.rpm SHA-256: b339189e0356297ba51a3f772faa3dd3fae54a01ea9cc054dfa7f0b116145322 evince-libs-debuginfo-40.5-2.el9_6.1.s390x.rpm SHA-256: d37bb86ac5826aa24de3f7713637d46cf27f7e5a272e2dd3f77624f362d06b86 evince-nautilus-40.5-2.el9_6.1.s390x.rpm SHA-256: 9610bab3b12606247d1db20f3c9d8c7b2ebe2cc1fd7190917e5beb38f7aabd1c evince-nautilus-debuginfo-40.5-2.el9_6.1.s390x.rpm SHA-256: b478628e2ebddac8bd3567c74c726a0ba21a6929bc365af5fa1f995a0cf1b9a4 evince-previewer-40.5-2.el9_6.1.s390x.rpm SHA-256: b07142fd745f104da23f17863bf3a3e526d4300714d090955ff887644688e1bb evince-previewer-debuginfo-40.5-2.el9_6.1.s390x.rpm SHA-256: baef72f532f4c5ba501f6fddded7e845a2cad5f8acbfa3e8c68c94983f47a6f5 evince-thumbnailer-40.5-2.el9_6.1.s390x.rpm SHA-256: eda5b5d4490c83a4018a200c1667034d666c773cd6b23766136e394f6b3cb29f evince-thumbnailer-debuginfo-40.5-2.el9_6.1.s390x.rpm SHA-256: 9f70c228ab8d56fb9a62b81ce2758cacd4da6d7770fa8a4b260bd6e624c2bc47 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRPM evince-40.5-2.el9_6.1.src.rpm SHA-256: fcc6ec69392d44dcaf55b50bd9a413e314dc3496441499234b6c97f97ddc184f ppc64le evince-40.5-2.el9_6.1.ppc64le.rpm SHA-256: ef915d64f4e075161afffbe4e44fc532fcd86dc419ccf8d6cb0f1d5555d04542 evince-debuginfo-40.5-2.el9_6.1.ppc64le.rpm SHA-256: 12e8fec4cd8c063e548d3c640fa65ef45724db038e74b25db770a0e3c4a170c3 evince-debugsource-40.5-2.el9_6.1.ppc64l

Share this article