Evince is a document viewer for multiple document formats. The goal of evince is to replace the multiple document viewers that exist on the GNOME Desktop with a single simple application. Evince is specifically designed to support the file following formats: PDF, Postscript, djvu, tiff, dvi, XPS, SyncTex support with gedit, comics books (cbr,cbz,cb7 and cbt).
Security Fix(es):
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is shell/ev-application.c:ev_spawn, which builds a command line from attacker-controlled PDF link-destination fields without applying g_shell_quote. The cmdline is then handed to g_app_info_create_from_commandline, which shell-parses it back into argv — splitting any embedded --gtk-module=PATH into a separate argv element. GTK then dlopen()s the path during init, running any __attribute__((constructor)) it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT --checkpoint-action injection in comics-document.c, fixed in 1.6.2) but in a different code path (shell/ev-application.c) that the original patch did not touch.(CVE-2026-46529)
{
"severity": "High"
}{
"x86_64": [
"evince-3.30.1-5.oe2003sp4.x86_64.rpm",
"evince-debuginfo-3.30.1-5.oe2003sp4.x86_64.rpm",
"evince-debugsource-3.30.1-5.oe2003sp4.x86_64.rpm",
"evince-devel-3.30.1-5.oe2003sp4.x86_64.rpm",
"evince-help-3.30.1-5.oe2003sp4.x86_64.rpm"
],
"aarch64": [
"evince-3.30.1-5.oe2003sp4.aarch64.rpm",
"evince-debuginfo-3.30.1-5.oe2003sp4.aarch64.rpm",
"evince-debugsource-3.30.1-5.oe2003sp4.aarch64.rpm",
"evince-devel-3.30.1-5.oe2003sp4.aarch64.rpm",
"evince-help-3.30.1-5.oe2003sp4.aarch64.rpm"
],
"src": [
"evince-3.30.1-5.oe2003sp4.src.rpm"
]
}
{
"x86_64": [
"evince-3.38.2-2.oe2203sp4.x86_64.rpm",
"evince-debuginfo-3.38.2-2.oe2203sp4.x86_64.rpm",
"evince-debugsource-3.38.2-2.oe2203sp4.x86_64.rpm",
"evince-devel-3.38.2-2.oe2203sp4.x86_64.rpm",
"evince-help-3.38.2-2.oe2203sp4.x86_64.rpm"
],
"aarch64": [
"evince-3.38.2-2.oe2203sp4.aarch64.rpm",
"evince-debuginfo-3.38.2-2.oe2203sp4.aarch64.rpm",
"evince-debugsource-3.38.2-2.oe2203sp4.aarch64.rpm",
"evince-devel-3.38.2-2.oe2203sp4.aarch64.rpm",
"evince-help-3.38.2-2.oe2203sp4.aarch64.rpm"
],
"src": [
"evince-3.38.2-2.oe2203sp4.src.rpm"
]
}
{
"x86_64": [
"evince-44.3-3.oe2403sp1.x86_64.rpm",
"evince-debuginfo-44.3-3.oe2403sp1.x86_64.rpm",
"evince-debugsource-44.3-3.oe2403sp1.x86_64.rpm",
"evince-devel-44.3-3.oe2403sp1.x86_64.rpm"
],
"aarch64": [
"evince-44.3-3.oe2403sp1.aarch64.rpm",
"evince-debuginfo-44.3-3.oe2403sp1.aarch64.rpm",
"evince-debugsource-44.3-3.oe2403sp1.aarch64.rpm",
"evince-devel-44.3-3.oe2403sp1.aarch64.rpm"
],
"src": [
"evince-44.3-3.oe2403sp1.src.rpm"
],
"noarch": [
"evince-help-44.3-3.oe2403sp1.noarch.rpm"
]
}
{
"x86_64": [
"evince-44.3-3.oe2403sp3.x86_64.rpm",
"evince-debuginfo-44.3-3.oe2403sp3.x86_64.rpm",
"evince-debugsource-44.3-3.oe2403sp3.x86_64.rpm",
"evince-devel-44.3-3.oe2403sp3.x86_64.rpm"
],
"aarch64": [
"evince-44.3-3.oe2403sp3.aarch64.rpm",
"evince-debuginfo-44.3-3.oe2403sp3.aarch64.rpm",
"evince-debugsource-44.3-3.oe2403sp3.aarch64.rpm",
"evince-devel-44.3-3.oe2403sp3.aarch64.rpm"
],
"src": [
"evince-44.3-3.oe2403sp3.src.rpm"
],
"noarch": [
"evince-help-44.3-3.oe2403sp3.noarch.rpm"
]
}