poppler uses std::atomic_int for reference counting. Because it is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. References: . MGASA-2025-0214 - Updated poppler packages fix security vulnerabilities Publication date: 25 Jul 2025 URL: https://advisories.mageia.org/MGASA-2025-0214.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-52886 poppler uses std::atomic_int for reference counting. Because it is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. References: - https://bugs.mageia.org/show_bug.cgi?id=34485 - https://www.openwall.com/lists/oss-security/2025/07/11/5 - https://www.cve.org/CVERecord?id=CVE-2025-52886 SRPMS: - 9/core/poppler-23.02.0-1.7.mga9 . Mageia security advisory MGASA-2025-0215 addresses a critical vulnerability in the libpng library's improper memory handling, along with appropriate updates for resolution.. Mageia Advisory, Poppler Update, Security Update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.