CVE-2026-93314

Source
https://cve.org/CVERecord?id=CVE-2026-93314
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93314.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93314
Downstream
Published
2026-09-18T01:30:10Z
Modified
2026-09-19T08:03:44Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Freedesktop Poppler FoFiTrueType.cc mapCodeToGID integer overflow
Details

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called ed2a5538cf0a8d3ff908191eda9b73f91a5f952a. It is advisable to implement a patch to correct this issue.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-189",
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93314.json"
}
References

Affected packages

Git / gitlab.freedesktop.org/poppler/poppler

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/poppler/poppler
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "26.07.0"
        },
        {
            "last_affected": "26.07.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

26.*
26.07.0
poppler-26.*
poppler-26.07.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93314.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "143589218451706217541690469329679103511",
                "218718971110406659054099285549161531180",
                "242691412447087393056767163932293511981",
                "158147833870649018376543384639753246732",
                "269631830359645129472325683501312857322",
                "129508230165488496465313868842280823895",
                "242352304971215259611721641239462737049",
                "135648280888751932382035725330882984324",
                "107547147164253111235715681873547752461",
                "306814227900423172613963046093981516927",
                "213199674334453852495872457832658356739",
                "214586282704966933512219267570932167289",
                "323880776810401969655168701350086217968",
                "265981560530189524410831692682159116988",
                "135045007302257789395044528308605937321"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-93314-353118ff",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://gitlab.freedesktop.org/poppler/poppler@ed2a5538cf0a8d3ff908191eda9b73f91a5f952a",
        "target": {
            "file": "fofi/FoFiTrueType.cc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "216034652194408936980011210245544307652",
            "length": 2732
        },
        "id": "CVE-2026-93314-801199f5",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://gitlab.freedesktop.org/poppler/poppler@ed2a5538cf0a8d3ff908191eda9b73f91a5f952a",
        "target": {
            "file": "fofi/FoFiTrueType.cc",
            "function": "FoFiTrueType::mapCodeToGID"
        }
    }
]
vanir_signatures_modified
"2026-09-19T08:03:44Z"