CVE-2026-10118

Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm)

Description

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

Metrics

Severity
high
no public PoC known
7.8
Source: nvd-v3
16.7 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-06-25 19:30 UTC
CWE-190

Weakness classes (CWE)

  • CWE-190Base

    Integer Overflow or Wraparound

    The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-21 19:10 UTC· nvd@nist.gov
    • Translation: Title: Poppler's Splash backend de varios productos de Red Hat, Description: Se encontró un fallo en el backend Splash de Poppler. Un atacante remoto podría explotar esta vulnerabilidad creando un archivo PDF malicioso que, al renderizarse, desencadena un desbordamiento de entero en la función 'tilingPatternFill'. Este desbordamiento conduce a una asignación de memoria de pila (heap) de tamaño insuficiente, permitiendo una escritura fuera de límites posterior. La explotación exitosa podría resultar en ejecución de código arbitrario, revelación de información o denegación de servicio dentro del contexto de la aplicación que procesa el PDF.
  2. CVE Modified2026-06-25 16:16 UTC· secalert@redhat.com
    • Reference: https://access.redhat.com/errata/RHSA-2026:29952
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8 (+14)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support (+14)
  3. CVE Modified2026-06-10 12:16 UTC· secalert@redhat.com
    • Reference: https://access.redhat.com/errata/RHSA-2026:25058
  4. CVE Modified2026-06-10 10:16 UTC· secalert@redhat.com
    • Reference: https://access.redhat.com/errata/RHSA-2026:24984
    • Reference: https://access.redhat.com/errata/RHSA-2026:24985

Affected operating systems

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_ai3.0

  • linux

    ubuntu / jqbionic

  • linux

    ubuntu / jqfocal

  • linux

    ubuntu / popplerjammy

  • linux

    ubuntu / popplernoble

  • linux

    ubuntu / popplerquesting

  • linux

    ubuntu / popplerresolute

  • other

    siemens / sinec_os

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • cryptography.io

    cryptography45.0.0 – 46.0.7

  • encode

    starlette0.8.3 – 1.0.1

  • encode

    starlette1.1.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • jqlang

    jq2026-04-12

  • libcap_project

    libcap

  • libsndfile_project

    libsndfile

  • libtiff

    libtiff

  • openbsd

    openssh10.3

  • openexr

    openexr3.1.0 – 3.2.7

  • openexr

    openexr3.3.0 – 3.3.9

  • openexr

    openexr3.4.0 – 3.4.9

  • pyasn1

    pyasn10.6.2

  • pyjwt_project

    pyjwt2.13.0

  • pypi

    vllm0.0.1

  • pypi

    vllm0.1.0

  • pypi

    vllm0.10.0

  • pypi

    vllm0.10.1

  • pypi

    vllm0.10.1.1

  • pypi

    vllm0.10.2

References & sources

Linked CVEs

IDCVE-2026-10118