Disclosure summary
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 245d3c6823377755f2c1d5fdddd010279c6ed94d. It is suggested to install a patch to address this issue.
Source-reported weakness categories
CWE-189, CWE-190
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-102620
Open original source · Updated Oct 02, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
- NIST NVD record
- CVE Program record
- github.com
- gitlab.freedesktop.org
- gitlab.freedesktop.org
- gitlab.freedesktop.org
- vuldb.com
- vuldb.com
- vuldb.com
- vuldb.com
PUBLISHED 2026-09-29T17:17:18-04:00
MODIFIED 2026-10-02T09:17:16-04:00
INGESTED 2026-10-06T11:43:05-04:00