The vulnerable code is only compiled when building with -DENABLE_DCTDECODER=unmaintained, which Debian does not use.
This CVE was originally filed against xpdf. While poppler shares some code history
with xpdf, the vulnerable path is not active in Debian's builds.
https://security-tracker.debian.org/tracker/CVE-2022-24106