---
cve: "CVE-2026-93312"
severity: "MEDIUM"
cvss: 5.3
epss: "0.6%"
vendor: "Freedesktop"
kev: false
exploited: false
published: "2026-09-18 01:16:56"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-10-03T22:33:38+02:00"
---

# CVE-2026-93312

> 5.3 MEDIUM · 🧪 PoC

## Beschreibung

A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **poc**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |

## Patch verfügbar (OSV)

- 5e49250f13b0390edeb3f90eb4c02c9941f97067 (Commit)

## BSI-Hinweise (deutsch)

- [poppler: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3454) — _BSI-Einstufung: mittel_
  Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in poppler ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen.

## Referenzen

- <https://vuldb.com/vuln/406610>
- <https://vuldb.com/vuln/406610/cti>
- <https://vuldb.com/cve/CVE-2026-93312>
- <https://vuldb.com/submit/942345>
- <https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1759>
- <https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2314>
- <https://github.com/r1ck9-2q/cve_summit/blob/main/Null-pointer-offset-undefined-behavior-in-JBIG2Stream-rewind-JBIG2Stream.cc-1229.md>
- <https://gitlab.freedesktop.org/poppler/poppler/-/commit/5e49250f13b0390edeb3f90eb4c02c9941f97067>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-93312) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
