[meta-oe][wrynose][PATCH] poppler: fix CVE-2026-10118

Abhishek Bachiphale <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <[email protected]>
A flaw was found in Poppler's Splash backend. A remote attacker could
exploit this vulnerability by crafting a malicious PDF file that, when
rendered, triggers an integer overflow in the `tilingPatternFill`
function. This overflow leads to an undersized heap memory allocation,
allowing a subsequent out-of-bounds write. Successful exploitation could
result in arbitrary code execution, information disclosure, or denial of
service within the context of the application processing the PDF.

Backport patch to fix CVE-2026-10118.

Reference:
[https://nvd.nist.gov/vuln/detail/CVE-2026-10118]
[https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1715]

Upstream Patch:
[https://gitlab.freedesktop.org/poppler/poppler/-/commit/8352264766652b98336e92359a70b3161a9ab97a]

Signed-off-by: Abhishek Bachiphale <[email protected]>
---
 .../poppler/poppler/CVE-2026-10118.patch      | 46 +++++++++++++++++++
 .../poppler/poppler_25.12.0.bb                |  1 +
 2 files changed, 47 insertions(+)
 create mode 100644 meta-oe/recipes-support/poppler/poppler/CVE-2026-10118.patch

diff --git a/meta-oe/recipes-support/poppler/poppler/CVE-2026-10118.patch b/meta-oe/recipes-support/poppler/poppler/CVE-2026-10118.patch
new file mode 100644
index 0000000000..ec4782efa8
--- /dev/null
+++ b/meta-oe/recipes-support/poppler/poppler/CVE-2026-10118.patch
@@ -0,0 +1,46 @@
+From 8352264766652b98336e92359a70b3161a9ab97a Mon Sep 17 00:00:00 2001
+From: Marek Kasik <[email protected]>
+Date: Thu, 21 May 2026 17:51:51 +0200
+Subject: [PATCH] SplashOutputDev: Fix integer overflow in tilingPatternFill
+
+Use checkedMultiply() to check integer multiplication of surface size
+and number of repetitions to avoid integer overflow and possible memory issues.
+
+Fixes: #1715
+
+CVE: CVE-2026-10118
+Upstream-Status: Backport [https://gitlab.freedesktop.org/poppler/poppler/-/commit/8352264766652b98336e92359a70b3161a9ab97a]
+
+Changes:
+- Removed copyright from the upstream patch
+
+Signed-off-by: Abhishek Bachiphale <[email protected]>
+---
+ poppler/SplashOutputDev.cc | 4 +---
+ 1 file changed, 1 insertions(+), 3 deletions(-)
+
+diff --git a/poppler/SplashOutputDev.cc b/poppler/SplashOutputDev.cc
+index ff3ad0eff..f055486c3 100644
+--- a/poppler/SplashOutputDev.cc
++++ b/poppler/SplashOutputDev.cc
+@@ -4327,7 +4328,7 @@ bool SplashOutputDev::tilingPatternFill(GfxState *state, Gfx *gfxA, Catalog * /*
+     matc[2] = ctm[2];
+     matc[3] = ctm[3];
+ 
+-    if (surface_width == 0 || surface_height == 0 || repeatX * repeatY <= 4) {
++    if (surface_width == 0 || surface_height == 0 || repeatX * repeatY <= 4 || checkedMultiply(surface_width, repeatX, &result_width) || checkedMultiply(surface_height, repeatY, &result_height)) {
+         state->setCTM(savedCTM[0], savedCTM[1], savedCTM[2], savedCTM[3], savedCTM[4], savedCTM[5]);
+         return false;
+     }
+@@ -4349,8 +4350,6 @@ bool SplashOutputDev::tilingPatternFill(GfxState *state, Gfx *gfxA, Catalog * /*
+         kx = matc[0];
+         ky = matc[3] - (matc[1] * matc[2]) / matc[0];
+     }
+-    result_width = surface_width * repeatX;
+-    result_height = surface_height * repeatY;
+     kx = result_width / (fabs(kx) + 1);
+     ky = result_height / (fabs(ky) + 1);
+     state->concatCTM(kx, 0, 0, ky, 0, 0);
+-- 
+GitLab
+
diff --git a/meta-oe/recipes-support/poppler/poppler_25.12.0.bb b/meta-oe/recipes-support/poppler/poppler_25.12.0.bb
index 71bff6d70d..57a7b996be 100644
--- a/meta-oe/recipes-support/poppler/poppler_25.12.0.bb
+++ b/meta-oe/recipes-support/poppler/poppler_25.12.0.bb
@@ -8,6 +8,7 @@ SRC_URI = "http://poppler.freedesktop.org/${BP}.tar.xz \
            file://basename-include.patch \
            file://0001-cmake-Do-not-use-isystem.patch \
            file://0001-workaround-build-racing.patch \
+           file://CVE-2026-10118.patch \
            "
 SRC_URI[sha256sum] = "c18b40eb36b1a0c5b86e29ca054bf0770304583da4f2cdd42fe86eca6a20de48"
 
-- 
2.40.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.