USN-8894-1: poppler flaws, update on Ubuntu 22.04, 24.04 and 26.04 LTS
Five vulnerabilities in poppler, the PDF rendering library, can cause crashes or code execution. Ubuntu has released patches for 22.04, 24.04 and 26.04 LTS.
UptimeMag editorial team · 7 October 2026 · 1 min read

Ubuntu published security advisory USN-8894-1 on 7 October 2026, covering five vulnerabilities in the poppler library, used for rendering PDF files. This affects anyone running servers that convert, index or display PDFs generated by external users: CMSs with document upload features, invoicing services, archiving tools, automated conversion pipelines.
The vulnerabilities
According to the official Ubuntu advisory, the issues are:
- CVE-2026-102620: integer overflow in
FoFiTrueType::cvtSfnts, which can cause a crash or arbitrary code execution. - CVE-2026-102621: integer overflow in
SplashClip::clipToPath, which can cause a crash or arbitrary code execution. - CVE-2026-93312: null pointer dereference in
JBIG2Stream, which can cause a denial of service. - CVE-2026-93313: integer overflow in
JBIG2Stream::readCodeTableSeg, which can cause a crash or arbitrary code execution. - CVE-2026-93314: integer overflow in
FoFiTrueType::mapCodeToGID, which can cause a crash or arbitrary code execution.
In every case, the attack vector is a specially crafted PDF file opened by poppler: if it's opened by a privileged process (e.g. a server-side conversion worker), the arbitrary code runs with those privileges, not with those of an anonymous user.
Packages to update
| Ubuntu release | Package | Fixed version |
|---|---|---|
| 26.04 LTS (resolute) | libpoppler156 | 26.01.0-2ubuntu0.2 |
| 24.04 LTS (noble) | libpoppler134 | 24.02.0-1ubuntu9.10 |
| 22.04 LTS (jammy) | libpoppler118 | 22.02.0-2ubuntu0.14 |
How to update
A standard system update will apply the fixed versions:
sudo apt update && sudo apt upgrade
Ubuntu Pro users get ten years of security coverage across more than 25,000 packages in the Main and Universe repositories; the service is free for up to 5 machines, as stated on the advisory page.
Anyone running poppler or tools that depend on it (e.g. pdftotext, pdftoppm, server-side conversions) should plan to update soon, especially if the service accepts PDF uploads from untrusted users.
Source: official Ubuntu Security Notices advisory, USN-8894-1.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.