- What: Security update for evince
- Impact: Fixes vulnerabilities in document viewer
Red Hat Product Errata RHSA-2026:39115 - Security Advisory Issued: 2026-07-14 Updated: 2026-07-14 RHSA-2026:39115 - Security Advisory Overview Updated Packages Synopsis Important: evince security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for evince is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The evince packages provide a simple multi-page document viewer for Portable Document Format (PDF), PostScript (PS), Encapsulated PostScript (EPS) files, and, with additional back-ends, also the Device Independent File format (DVI) files. Security Fix(es): atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen (CVE-2026-46529) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2487669 - CVE-2026-46529 atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen CVEs CVE-2026-46529 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM evince-40.5-2.el9_2.1.src.rpm SHA-256: 1d54eeed7b1917a277fdeea99656317fa897e2716314fb1a938d12c6286ed9bc x86_64 evince-40.5-2.el9_2.1.x86_64.rpm SHA-256: 73620509bd2ce8d051d270b0f6b0daa8057f8365052fb71f5b6b5559c7b3c6ce evince-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: 79fe5581b62bdea3f161985b792b768af313a1d364436d0128db152534da5b6c evince-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: 7e59ba3a974eb77264917e979ebff9e19e0606d397bd29c48ff186afedc183f7 evince-debugsource-40.5-2.el9_2.1.i686.rpm SHA-256: 2fe971ff1983fcdde2d2b7371e0e783c35b1f89be492372b35acd964570f588a evince-debugsource-40.5-2.el9_2.1.x86_64.rpm SHA-256: c0c5e0dd631c59d47b6b70d72b2a0ba1191ad50ae66d20ca802e197520ef4558 evince-dvi-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: 080b500e73bafbee7aa3fb017ec0deb1d779a5e643dc1b5ba37a91251249d52a evince-dvi-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: 75793dac4c52ca29584320676686d4152accad3bfcca1f63ca339017f2ebbbe4 evince-libs-40.5-2.el9_2.1.i686.rpm SHA-256: 5e5ea208c72364373faa69839a46eb10a08d0b55c0f6b79dc7ff88ba27825fe1 evince-libs-40.5-2.el9_2.1.x86_64.rpm SHA-256: 0d7827259ecb9a1e23a00a61de355057784ed3da48b546152e49feba99add35f evince-libs-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: 5c7f34b26bb44c680fdf1e75b7a75f8ca8d1b9d32e469868eaee897d55713cc7 evince-libs-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: 206d1fe156e2fdd3bcf047281c45dbd5b4b5f9c3f2341535f6e226935cdb1575 evince-nautilus-40.5-2.el9_2.1.x86_64.rpm SHA-256: 24d2128ca4cf1c8ee10f707a24e2223d7d1655ff66dabd425c2b862b3d02a363 evince-nautilus-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: 368156007f94df700d4f49b46b54f09772b44cb17b995ea7aa0aa4e6a95284c4 evince-nautilus-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: b6e64e72350d6b326a77f50f9ee1eff5b4b9a5fdfbd07d428fce35a8ba7fc34e evince-previewer-40.5-2.el9_2.1.x86_64.rpm SHA-256: 739ee7ddde909f91c5d648043d21ff3486597503ecf28174bffef8fec8d02e84 evince-previewer-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: 4b66e35257dbe8489ce27e54449344b749d208c1e4ad0d0ecd2cb39836ea53b1 evince-previewer-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: 531ba69c7db4c982878461403bff4f58a6b93115b546bb4494d421b52ab05dc4 evince-thumbnailer-40.5-2.el9_2.1.x86_64.rpm SHA-256: 29774874fac3e2f585b5dca192273a110f1cf7825844ab49a7e2f32f044ec7da evince-thumbnailer-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: e51922e492e40bcea251377b9262695cc54b2fac29231f7c5007a1f4bdb598fa evince-thumbnailer-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: 1a89ccddb34b49e61937c35a411261c4a50f96118415b34234adf16b6c0a1d43 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM evince-40.5-2.el9_2.1.src.rpm SHA-256: 1d54eeed7b1917a277fdeea99656317fa897e2716314fb1a938d12c6286ed9bc ppc64le evince-40.5-2.el9_2.1.ppc64le.rpm SHA-256: 25df6cff27429b0d8e97c8b629dcc58806fa5ae197696aee9cb65d103d37f85f evince-debuginfo-40.5-2.el9_2.1.ppc64le.rpm SHA-256: 2c05899203db34bbe8fc26da54c543785c77402894be1e25a96f9c0c86889ce8 evince-debugsource-40.5-2.el9_2.1.ppc64le.rpm SHA-256: 2dacaa4a7e29571c962338ebabfe63a8204710eae770affab645f7d1c83934b5 evince-dvi-debuginfo-40.5-2.el9_2.1.ppc64le.rpm SHA-256: f2ac52a4db684499ed020725a3a2e3e95d1ac5b1482bf334068dfc9b826392be evince-libs-40.5-2.el9_2.1.ppc64le.rpm SHA-256: 7e0c6f6eea0895751647932aa0d1c0eb46a5dc56e58ffc2b952039d2e43e664a evince-libs-debuginfo-40.5-2.el9_2.1.ppc64le.rpm SHA-256: 28fe5f85fee92d995f44d5e94345c3405fdaaa970ac1535f1ef4f40defd0c4d7 evince-nautilus-40.5-2.el9_2.1.ppc64le.rpm SHA-256: f3f9f0d095c21c6f8743b1fcbdb09a911b0dfb846c7d18aedfaad60679cd3c02 evince-nautilus-debuginfo-40.5-2.el9_2.1.ppc64le.rpm SHA-256: d8091e792ffa4e486a390ca1cd039ad8d0cb7d9a99d09aede5c4a82a268030fe evince-previewer-40.5-2.el9_2.1.ppc64le.rpm SHA-256: 00f0d0ca091d91c72fb7235be526d354c65478784d416810eab9d2fb4efa3dd4 evince-previewer-debuginfo-40.5-2.el9_2.1.ppc64le.rpm SHA-256: f9b75bc9fa8d9bc2eae1dd0b709c492f601554269de73fa020a2c22a36d5df57 evince-thumbnailer-40.5-2.el9_2.1.ppc64le.rpm SHA-256: 466efb94fce7638e01ff460f01782f114947c06fd5c3cf82b1c51658f0170165 evince-thumbnailer-debuginfo-40.5-2.el9_2.1.ppc64le.rpm SHA-256: b0a58f13e7a252516fae2cabfc64435ceec3524dde0f1d6486b75ffd0c1bd26b Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM evince-40.5-2.el9_2.1.src.rpm SHA-256: 1d54eeed7b1917a277fdeea99656317fa897e2716314fb1a938d12c6286ed9bc x86_64 evince-40.5-2.el9_2.1.x86_64.rpm SHA-256: 73620509bd2ce8d051d270b0f6b0daa8057f8365052fb71f5b6b5559c7b3c6ce evince-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: 79fe5581b62bdea3f161985b792b768af313a1d364436d0128db152534da5b6c evince-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: 7e59ba3a974eb77264917e979ebff9e19e0606d397bd29c48ff186afedc183f7 evince-debugsource-40.5-2.el9_2.1.i686.rpm SHA-256: 2fe971ff1983fcdde2d2b7371e0e783c35b1f89be492372b35acd964570f588a evince-debugsource-40.5-2.el9_2.1.x86_64.rpm SHA-256: c0c5e0dd631c59d47b6b70d72b2a0ba1191ad50ae66d20ca802e197520ef4558 evince-dvi-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: 080b500e73bafbee7aa3fb017ec0deb1d779a5e643dc1b5ba37a91251249d52a evince-dvi-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: 75793dac4c52ca29584320676686d4152accad3bfcca1f63ca339017f2ebbbe4 evince-libs-40.5-2.el9_2.1.i686.rpm SHA-256: 5e5ea208c72364373faa69839a46eb10a08d0b55c0f6b79dc7ff88ba27825fe1 evince-libs-40.5-2.el9_2.1.x86_64.rpm SHA-256: 0d7827259ecb9a1e23a00a61de355057784ed3da48b546152e49feba99add35f evince-libs-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: 5c7f34b26bb44c680fdf1e75b7a75f8ca8d1b9d32e469868eaee897d55713cc7 evince-libs-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: 206d1fe156e2fdd3bcf047281c45dbd5b4b5f9c3f2341535f6e226935cdb1575 evince-nautilus-40.5-2.el9_2.1.x86_64.rpm SHA-256: 24d2128ca4cf1c8ee10f707a24e2223d7d1655ff66dabd425c2b862b3d02a363 evince-nautilus-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: 368156007f94df700d4f49b46b54f09772b44cb17b995ea7aa0aa4e6a95284c4 evince-nautilus-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: b6e64e72350d6b326a77f50f9ee1eff5b4b9a5fdfbd07d428fce35a8ba7fc34e evince-previewer-40.5-2.el9_2.1.x86_64.rpm SHA-256: 739ee7ddde909f91c5d648043d21ff3486597503ecf28174bffef8fec8d02e84 evince-previewer-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: 4b66e35257dbe8489ce27e54449344b749d208c1e4ad0d0ecd2cb39836ea53b1 evince-previewer-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: 531ba69c7db4c982878461403bff4f58a6b93115b546bb4494d421b52ab05dc4 evince-thumbnailer-40.5-2.el9_2.1.x86_64.rpm SHA-256: 29774874fac3e2f585b5dca192273a110f1cf7825844ab49a7e2f32f044ec7da evince-thumbnailer-debuginfo-40.5-2.el9_2.1.i686.rpm SHA-256: e51922e492e40bcea251377b9262695cc54b2fac29231f7c5007a1f4bdb598fa evince-thumbnailer-debuginfo-40.5-2.el9_2.1.x86_64.rpm SHA-256: 1a89ccddb34b49e61937c35a411261c4a50f96118415b34234adf16b6c0a1d43 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 SRPM evince-40.5-2.el9_2.1.src.rpm SHA-256: 1d54eeed7b1917a277fdeea99656317fa897e2716314fb1a938d12c6286ed9bc aarch64 evince-40.5-2.el9_2.1.aarch64.rpm SHA-256: d132d97b488057ff99e91705afdfef4b447ab3350f7a60ac16ae2a069cc4af7e evince-debuginfo-40.5-2.el9_2.1.aarch64.rpm SHA-256: c8af57743b2b5723527e69b0ae14586fa8530d6975a7450818b9952aa812fc83 evince-debugsource-40.5-2.el9_2.1.aarch64.rpm SHA-256: 44fd0beb82b667e8c35a7bed4bd8215ac2634aa36553c6c1d0a215e7807712c8 evince-dvi-debuginfo-40.5-2.el9_2.1.aarch64.rpm SHA-256: 381b229bdf78042757ce5ac8d41631ccb2dfc1ea0ef350a1a6e54d6fcedeaef4 evince-libs-40.5-2.el9_2.1.aarch64.rpm SHA-256: eabb420a6c0065e09e99bf62b