A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 245d3c6823377755f2c1d5fdddd010279c6ed94d. It is suggested to install a patch to address this issue.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-189",
"CWE-190"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102620.json"
}{
"extracted_events": [
{
"introduced": "26.06.0"
},
{
"last_affected": "26.06.0"
},
{
"introduced": "26.07.0"
},
{
"last_affected": "26.07.0"
},
{
"introduced": "26.08.0"
},
{
"last_affected": "26.08.0"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102620.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"316507151484651850106579660930279721617",
"13671424488171877063658175664268792836",
"258944320358568011424618016349063333571",
"249304604168044265085743981136774797565"
],
"threshold": 0.9
},
"id": "CVE-2026-102620-209e3c86",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://gitlab.freedesktop.org/poppler/poppler@245d3c6823377755f2c1d5fdddd010279c6ed94d",
"target": {
"file": "fofi/FoFiTrueType.cc"
}
}
]
"2026-10-01T08:05:48Z"