Alerts This Week
Warning Icon 1 500
Alerts This Week
Warning Icon 1 500

Debian 12 atril Critical Command Injection Fix DLA-4632-1 CVE-2026-46529

debian lts
Calendar Grey June 16, 2026
Dist Debian Esm H88
Critical atril update addresses command injection threat in Debian LTS. Ensure your systems are patched for security.
It was discovered that atril, a simple multi-page document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened

Summary

For Debian 12 bookworm, this problem has been fixed in version
1.26.0-2+deb12u4.

For Debian 11 bullseye, see DLA 4597-1.

We recommend that you upgrade your atril packages.

For the detailed security status of atril please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/atril

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: atril
Version: 1.26.0-2+deb12u4
CVE ID: CVE-2026-46529
Debian Bug: 1139874

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here