DEBIAN-CVE-2026-46529

Source
https://security-tracker.debian.org/tracker/CVE-2026-46529
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46529.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-46529
Upstream
Published
2026-06-10T20:17:28Z
Modified
2026-09-14T17:03:17Z
Severity
  • 8.4 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is shell/ev-application.c:ev_spawn, which builds a command line from attacker-controlled PDF link-destination fields without applying g_shell_quote. The cmdline is then handed to g_app_info_create_from_commandline, which shell-parses it back into argv — splitting any embedded --gtk-module=PATH into a separate argv element. GTK then dlopen()s the path during init, running any __attribute__((constructor)) it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT --checkpoint-action injection in comics-document.c, fixed in 1.6.2) but in a different code path (shell/ev-application.c) that the original patch did not touch.

References

Affected packages

Debian:12
atril

Package

Name
atril
Purl
pkg:deb/debian/atril?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.26.0-2+deb12u4

Affected versions

1.*
1.26.0-2
1.26.0-2+deb12u1
1.26.0-2+deb12u2
1.26.0-2+deb12u3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46529.json"
evince

Package

Name
evince
Purl
pkg:deb/debian/evince?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
43.1-2+deb12u1

Affected versions

43.*
43.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46529.json"
Debian:13
atril

Package

Name
atril
Purl
pkg:deb/debian/atril?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.26.2-4+deb13u1

Affected versions

1.*
1.26.2-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46529.json"
evince

Package

Name
evince
Purl
pkg:deb/debian/evince?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
48.1-3+deb13u1

Affected versions

48.*
48.1-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46529.json"
papers

Package

Name
papers
Purl
pkg:deb/debian/papers?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

48.*
48.3-1
48.5-1
49.*
49.0-1
49.0-2
49.0-3
49.1-1
49.2-1
49.2-2
49.2-3
49.3-1
49.3-2
49.3-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46529.json"
Debian:14
atril

Package

Name
atril
Purl
pkg:deb/debian/atril?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.28.4-1

Affected versions

1.*
1.26.2-4
1.26.2-5
1.28.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46529.json"
evince

Package

Name
evince
Purl
pkg:deb/debian/evince?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
49~alpha-3

Affected versions

48.*
48.1-3
48.1-4
Other
49~alpha-1
49~alpha-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46529.json"
evince-gtk3

Package

Name
evince-gtk3
Purl
pkg:deb/debian/evince-gtk3?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
48.4+dfsg-1

Affected versions

48.*
48.1+dfsg-1
48.1+dfsg-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46529.json"
papers

Package

Name
papers
Purl
pkg:deb/debian/papers?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
49.3-3

Affected versions

48.*
48.3-1
48.5-1
49.*
49.0-1
49.0-2
49.0-3
49.1-1
49.2-1
49.2-2
49.2-3
49.3-1
49.3-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46529.json"