CVE-2026-10118
Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm)
Beschreibung
Ein Fehler wurde im Splash-Backend von Poppler gefunden. Ein Fernangreifer könnte diese Schwachstelle ausnutzen, indem er eine bösartige PDF-Datei erstellt, die beim Rendern einen Überlauf eines Ganzzahls in der Funktion `tilingPatternFill` verursacht. Dieser Überlauf führt zu einer unzureichenden Speicherzuweisung im Heap-Speicher und ermöglicht anschließend einen Schreibzugriff außerhalb des gültigen Bereichs. Eine erfolgreiche Ausnutzung könnte zur willkürlichen Codeausführung, Offenlegung von Informationen oder zum Dienstverweigerungsangriff innerhalb des Kontextes der Anwendung führen, die das PDF verarbeitet.
Metriken
Weakness-Klassen (CWE)
CWE-190Base
Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Translated2026-07-21 19:10 UTC· nvd@nist.gov
- Translation: Title: Poppler's Splash backend de varios productos de Red Hat, Description: Se encontró un fallo en el backend Splash de Poppler. Un atacante remoto podría explotar esta vulnerabilidad creando un archivo PDF malicioso que, al renderizarse, desencadena un desbordamiento de entero en la función 'tilingPatternFill'. Este desbordamiento conduce a una asignación de memoria de pila (heap) de tamaño insuficiente, permitiendo una escritura fuera de límites posterior. La explotación exitosa podría resultar en ejecución de código arbitrario, revelación de información o denegación de servicio dentro del contexto de la aplicación que procesa el PDF.
- CVE Modified2026-06-25 16:16 UTC· secalert@redhat.com
- Reference: https://access.redhat.com/errata/RHSA-2026:29952
- Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8 (+14) → Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support (+14)
- CVE Modified2026-06-10 12:16 UTC· secalert@redhat.com
- Reference: https://access.redhat.com/errata/RHSA-2026:25058
- CVE Modified2026-06-10 10:16 UTC· secalert@redhat.com
- Reference: https://access.redhat.com/errata/RHSA-2026:24984
- Reference: https://access.redhat.com/errata/RHSA-2026:24985
Betroffene Betriebssysteme
linux
debian / debian_linux11.0
linux
redhat / enterprise_linux10.0
linux
redhat / enterprise_linux6.0
linux
redhat / enterprise_linux7.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
linux
redhat / enterprise_linux_ai3.0
linux
ubuntu / jqbionic
linux
ubuntu / jqfocal
linux
ubuntu / popplerjammy
linux
ubuntu / popplernoble
linux
ubuntu / popplerquesting
linux
ubuntu / popplerresolute
other
siemens / sinec_os
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
bitnami
python-min3.11.0
bitnami
python-min3.12.0
bitnami
python-min3.13.0
bitnami
python-min3.14.0
cryptography.io
cryptography45.0.0 – 46.0.7
encode
starlette0.8.3 – 1.0.1
encode
starlette1.1.0
IBM
QRadar SIEM<7.5.0 UP15 IF06
jqlang
jq2026-04-12
libcap_project
libcap
libsndfile_project
libsndfile
libtiff
libtiff
openbsd
openssh10.3
openexr
openexr3.1.0 – 3.2.7
openexr
openexr3.3.0 – 3.3.9
openexr
openexr3.4.0 – 3.4.9
pyasn1
pyasn10.6.2
pyjwt_project
pyjwt2.13.0
pypi
vllm0.0.1
pypi
vllm0.1.0
pypi
vllm0.10.0
pypi
vllm0.10.1
pypi
vllm0.10.1.1
pypi
vllm0.10.2
Quellen & Referenzen
- https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9x_refsource_CONFIRM
- https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615x_refsource_MISC
- https://github.com/vim/vim/releases/tag/v9.2.0276x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2026/04/01/1
- https://access.redhat.com/security/cve/CVE-2026-34982vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2455400issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34982.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:30900vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:11389vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19073vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:11509vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:33453vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:34477vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:34476vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28133vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28049vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28050vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:11510vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19224vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:36004vendor-advisoryx_refsource_REDHAT
Verknüpfte CVEs
- CVE-2026-6100
Ein Verwendungsfehler nach Freigabe (Use-after-free, UAF) war im `lzma.LZMADecompressor`, `bz2.BZ2Decompressor` und `gzip.GzipFile` mögli…
criticalCVSSv3 8.1 - CVE-2026-48818
Starlette ist ein leichtgewichtiges ASGI-Framework/Toolkit.
highCVSSv3 7.5 - CVE-2026-4878
Ein Fehler wurde in libcap gefunden.
highCVSSv3 7.0 - CVE-2026-48746
vLLM ist ein Inferenz- und Bereitstellungsmotor für große Sprachmodelle (LLMs).
criticalCVSSv3 9.1 - CVE-2026-48710Aktiv ausgenutzt
Starlette ist ein leichtgewichtiges ASGI-Framework/Toolkit.
criticalCVSSv3 6.5 - CVE-2026-48526
PyJWT ist eine Implementierung von JSON Web Token in Python.
highCVSSv3 7.4 - CVE-2026-4786
Die Minderung von CVE-2026-4519 war unvollständig.
highCVSSv3 7.1 - CVE-2026-4775
Ein Fehler wurde in der libtiff-Bibliothek gefunden.
highCVSSv3 7.8 - CVE-2026-44432
urllib3 ist eine HTTP-Client-Bibliothek für Python.
highCVSSv3 7.5 - CVE-2026-44431
Urllib3 ist eine HTTP-Client-Bibliothek für Python.
high - CVE-2026-40164
jq ist ein Befehlszeilen-JSON-Prozessor.
highCVSSv3 7.5 - CVE-2026-39979
jq ist ein Befehlszeilen-JSON-Prozessor.
mediumCVSSv3 6.5 - CVE-2026-39892
Die Kryptographie ist ein Paket, das kryptografische Primitive und Rezepte für Python-Entwickler bereitstellt.
criticalCVSSv3 9.8 - CVE-2026-37555
Ein Problem wurde in der libsndfile 1.2.2 IMA ADPCM-Codierung entdeckt.
highCVSSv3 7.5 - CVE-2026-35535
Ein Fehler wurde bei Sudo gefunden.
highCVSSv3 7.8 - CVE-2026-35385
In OpenSSH vor Version 10.3 kann eine mit `scp` heruntergeladene Datei als setuid oder setgid installiert werden, was dem Erwartungsbild…
highCVSSv3 8.1 - CVE-2026-34982
Vim ist ein quelloffenes Texteditor für die Kommandozeile.
highCVSSv3 8.2 - CVE-2026-34588
OpenEXR stellt die Spezifikation und Referenzimplementierung des EXR-Dateiformats bereit, einem Bildspeicherformat für die Filmindustrie.
highCVSSv3 7.8 - CVE-2026-24779
vLLM ist ein Inferenz- und Bereitstellungsmotor für große Sprachmodelle (LLMs).
highCVSSv3 7.1 - CVE-2026-23490
pyasn1 ist eine generische ASN.1-Bibliothek für Python.
highCVSSv3 7.5 - CVE-2026-22807
vLLM ist ein Inferenz- und Bereitstellungsmotor für große Sprachmodelle (LLMs).
highCVSSv3 8.8 - CVE-2026-22778
vLLM ist ein Inferenz- und Bereitstellungsmotor für große Sprachmodelle (LLMs).
criticalCVSSv3 9.8