News

USN-8894-1: poppler flaws, update on Ubuntu 22.04, 24.04 and 26.04 LTS

Five vulnerabilities in poppler, the PDF rendering library, can cause crashes or code execution. Ubuntu has released patches for 22.04, 24.04 and 26.04 LTS.

UptimeMag editorial team · 7 October 2026 · 1 min read

USN-8894-1: falle in poppler, aggiornare su Ubuntu 22.04, 24.04 e 26.04 LTS

Ubuntu published security advisory USN-8894-1 on 7 October 2026, covering five vulnerabilities in the poppler library, used for rendering PDF files. This affects anyone running servers that convert, index or display PDFs generated by external users: CMSs with document upload features, invoicing services, archiving tools, automated conversion pipelines.

The vulnerabilities

According to the official Ubuntu advisory, the issues are:

  • CVE-2026-102620: integer overflow in FoFiTrueType::cvtSfnts, which can cause a crash or arbitrary code execution.
  • CVE-2026-102621: integer overflow in SplashClip::clipToPath, which can cause a crash or arbitrary code execution.
  • CVE-2026-93312: null pointer dereference in JBIG2Stream, which can cause a denial of service.
  • CVE-2026-93313: integer overflow in JBIG2Stream::readCodeTableSeg, which can cause a crash or arbitrary code execution.
  • CVE-2026-93314: integer overflow in FoFiTrueType::mapCodeToGID, which can cause a crash or arbitrary code execution.

In every case, the attack vector is a specially crafted PDF file opened by poppler: if it's opened by a privileged process (e.g. a server-side conversion worker), the arbitrary code runs with those privileges, not with those of an anonymous user.

Packages to update

Ubuntu release Package Fixed version
26.04 LTS (resolute) libpoppler156 26.01.0-2ubuntu0.2
24.04 LTS (noble) libpoppler134 24.02.0-1ubuntu9.10
22.04 LTS (jammy) libpoppler118 22.02.0-2ubuntu0.14

How to update

A standard system update will apply the fixed versions:

sudo apt update && sudo apt upgrade

Ubuntu Pro users get ten years of security coverage across more than 25,000 packages in the Main and Universe repositories; the service is free for up to 5 machines, as stated on the advisory page.

Anyone running poppler or tools that depend on it (e.g. pdftotext, pdftoppm, server-side conversions) should plan to update soon, especially if the service accepts PDF uploads from untrusted users.

Source: official Ubuntu Security Notices advisory, USN-8894-1.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.