Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
RHSA-2026:28998
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:28998
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:28998.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2026:28998
Upstream
CVE-2026-46529
Published
2026-06-25T10:43:03Z
Modified
2026-06-26T12:23:00.894264179Z
Severity
7.8 (High)
CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: evince security update
Details
References
https://access.redhat.com/errata/RHSA-2026:28998
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=2487669
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_28998.json
https://access.redhat.com/security/cve/CVE-2026-46529
https://www.cve.org/CVERecord?id=CVE-2026-46529
https://nvd.nist.gov/vuln/detail/CVE-2026-46529
http://www.openwall.com/lists/oss-security/2026/05/19/34
http://www.openwall.com/lists/oss-security/2026/05/21/7
http://www.openwall.com/lists/oss-security/2026/05/22/11
https://github.com/mate-desktop/atril/releases/tag/v1.26.3
https://github.com/mate-desktop/atril/releases/tag/v1.28.4
https://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f
https://lists.debian.org/debian-lts-announce/2026/05/msg00041.html
https://lists.debian.org/debian-lts-announce/2026/05/msg00042.html
Affected packages
Red Hat:enterprise_linux:8::appstream
evince
Package
Name
evince
Purl
pkg:rpm/redhat/evince
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-browser-plugin
Package
Name
evince-browser-plugin
Purl
pkg:rpm/redhat/evince-browser-plugin
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-browser-plugin-debuginfo
Package
Name
evince-browser-plugin-debuginfo
Purl
pkg:rpm/redhat/evince-browser-plugin-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-debuginfo
Package
Name
evince-debuginfo
Purl
pkg:rpm/redhat/evince-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-debugsource
Package
Name
evince-debugsource
Purl
pkg:rpm/redhat/evince-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-libs
Package
Name
evince-libs
Purl
pkg:rpm/redhat/evince-libs
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-libs-debuginfo
Package
Name
evince-libs-debuginfo
Purl
pkg:rpm/redhat/evince-libs-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-nautilus
Package
Name
evince-nautilus
Purl
pkg:rpm/redhat/evince-nautilus
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-nautilus-debuginfo
Package
Name
evince-nautilus-debuginfo
Purl
pkg:rpm/redhat/evince-nautilus-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
Red Hat:enterprise_linux:8::crb
evince-browser-plugin-debuginfo
Package
Name
evince-browser-plugin-debuginfo
Purl
pkg:rpm/redhat/evince-browser-plugin-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-debuginfo
Package
Name
evince-debuginfo
Purl
pkg:rpm/redhat/evince-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-debugsource
Package
Name
evince-debugsource
Purl
pkg:rpm/redhat/evince-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-devel
Package
Name
evince-devel
Purl
pkg:rpm/redhat/evince-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-libs-debuginfo
Package
Name
evince-libs-debuginfo
Purl
pkg:rpm/redhat/evince-libs-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
evince-nautilus-debuginfo
Package
Name
evince-nautilus-debuginfo
Purl
pkg:rpm/redhat/evince-nautilus-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.28.4-17.el8_10
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:28998.json"
RHSA-2026:28998 - OSV