Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:46467: Important: evince security update

A critical vulnerability (CVE-2026-46529, CVSS 7.8 High) in the Evince document viewer allows for single-click remote code execution via a crafted PDF file that exploits an argument vector injection in the PDF /GoToR action. The flaw enables RCE through the `--gtk-module` dlopen mechanism. Red Hat has released patched packages for Evince on RHEL 8.6 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On.
Read Full Article →

Red Hat Product Errata RHSA-2026:46467 - Security Advisory Issued: 2026-07-27 Updated: 2026-07-27 RHSA-2026:46467 - Security Advisory Overview Updated Packages Synopsis Important: evince security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for evince is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The evince packages provide a simple multi-page document viewer for Portable Document Format (PDF), PostScript (PS), Encapsulated PostScript (EPS) files, and, with additional back-ends, also the Device Independent File format (DVI) files. Security Fix(es): atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen (CVE-2026-46529) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2487669 - CVE-2026-46529 atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen CVEs CVE-2026-46529 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 SRPM evince-3.28.4-16.el8_6.1.src.rpm SHA-256: b969790f22b5c89b503605f9af4aa254670f8e7ee7e2ea2d4ae1a9a93962f47d x86_64 evince-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: 1f193725c62b2813563c8eb10b0121dd015e6bdc7a87f21abbbadca12806b56e evince-browser-plugin-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: ccb781b9be0be9cbe3b70dc5de89c3276c5cc25278e5d598b3834eb1c311da7b evince-browser-plugin-debuginfo-3.28.4-16.el8_6.1.i686.rpm SHA-256: 7eb4cf8c85d86890c3920ea1992007193d7d21fb12810bd10a0fad45246561ef evince-browser-plugin-debuginfo-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: be11ab61e888131558c5d8ac526e440ed2259bc9852a2c8de0f1bac3ff4c0d08 evince-debuginfo-3.28.4-16.el8_6.1.i686.rpm SHA-256: 481cec6d1647d91d51aa0b441b449a71cc6809e5b64dbe5c1172d00286ce2fe8 evince-debuginfo-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: 32b4f36c38f0f83863f6f2da4178afe49e12746b09b71d6cf633b32b2a0c839a evince-debugsource-3.28.4-16.el8_6.1.i686.rpm SHA-256: 497765f833b85dab8d3ce050cb968bb81ce793e85da8844baa84cbd8152d8e41 evince-debugsource-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: fff8b431143ed199e591317334977e6a48e1a68682be65ae0fd68957bf886e48 evince-libs-3.28.4-16.el8_6.1.i686.rpm SHA-256: bb6318d894cebb1470bc8d4afd8801bf386065e4aef6fb25d33988d75a026678 evince-libs-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: 60424dc1950c9287417ddcd30616bd403dd17133ab9d705671370d2cef23ec30 evince-libs-debuginfo-3.28.4-16.el8_6.1.i686.rpm SHA-256: 492d6e636a2d7796e9e61b6b50529e9ce50714a56b01a5df1f3d5e6e2fc23db5 evince-libs-debuginfo-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: 1d03568e01d950530c6fbdd6003853405e960f66c3c6969ce891f9b8d09eca99 evince-nautilus-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: f73ca9cbf23b0be0d825d70e8cb4d18a108e4fcdc588542bb11c0e20794ef7c8 evince-nautilus-debuginfo-3.28.4-16.el8_6.1.i686.rpm SHA-256: 39c7055a6b58ddbee7c17cb5b332686184bdac43703aaf9ebff5751260297bd6 evince-nautilus-debuginfo-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: e43d9230a4af13da041c988d8909534b2c5d32049828b6b596cac0b9338f6d8c Red Hat Enterprise Linux Server - AUS 8.6 SRPM evince-3.28.4-16.el8_6.1.src.rpm SHA-256: b969790f22b5c89b503605f9af4aa254670f8e7ee7e2ea2d4ae1a9a93962f47d x86_64 evince-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: 1f193725c62b2813563c8eb10b0121dd015e6bdc7a87f21abbbadca12806b56e evince-browser-plugin-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: ccb781b9be0be9cbe3b70dc5de89c3276c5cc25278e5d598b3834eb1c311da7b evince-browser-plugin-debuginfo-3.28.4-16.el8_6.1.i686.rpm SHA-256: 7eb4cf8c85d86890c3920ea1992007193d7d21fb12810bd10a0fad45246561ef evince-browser-plugin-debuginfo-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: be11ab61e888131558c5d8ac526e440ed2259bc9852a2c8de0f1bac3ff4c0d08 evince-debuginfo-3.28.4-16.el8_6.1.i686.rpm SHA-256: 481cec6d1647d91d51aa0b441b449a71cc6809e5b64dbe5c1172d00286ce2fe8 evince-debuginfo-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: 32b4f36c38f0f83863f6f2da4178afe49e12746b09b71d6cf633b32b2a0c839a evince-debugsource-3.28.4-16.el8_6.1.i686.rpm SHA-256: 497765f833b85dab8d3ce050cb968bb81ce793e85da8844baa84cbd8152d8e41 evince-debugsource-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: fff8b431143ed199e591317334977e6a48e1a68682be65ae0fd68957bf886e48 evince-libs-3.28.4-16.el8_6.1.i686.rpm SHA-256: bb6318d894cebb1470bc8d4afd8801bf386065e4aef6fb25d33988d75a026678 evince-libs-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: 60424dc1950c9287417ddcd30616bd403dd17133ab9d705671370d2cef23ec30 evince-libs-debuginfo-3.28.4-16.el8_6.1.i686.rpm SHA-256: 492d6e636a2d7796e9e61b6b50529e9ce50714a56b01a5df1f3d5e6e2fc23db5 evince-libs-debuginfo-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: 1d03568e01d950530c6fbdd6003853405e960f66c3c6969ce891f9b8d09eca99 evince-nautilus-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: f73ca9cbf23b0be0d825d70e8cb4d18a108e4fcdc588542bb11c0e20794ef7c8 evince-nautilus-debuginfo-3.28.4-16.el8_6.1.i686.rpm SHA-256: 39c7055a6b58ddbee7c17cb5b332686184bdac43703aaf9ebff5751260297bd6 evince-nautilus-debuginfo-3.28.4-16.el8_6.1.x86_64.rpm SHA-256: e43d9230a4af13da041c988d8909534b2c5d32049828b6b596cac0b9338f6d8c The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article