CVE-2026-85458

Description

A flaw was found in Xpdf. This vulnerability, a divide-by-zero error, occurs when the application processes a Type 3 font glyph that has a zero height. A local attacker could exploit this condition to trigger a crash, leading to a denial of service and making the application unavailable.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Mitigation

Users should avoid opening untrusted PDF documents with Xpdf. If Xpdf is not essential, consider removing the package to eliminate the attack surface. For example, on Red Hat Enterprise Linux, the `xpdf` package can be removed using `sudo dnf remove xpdf`. Removing this package may affect other applications that depend on it.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Crash, Exit, or Restart

A Divide by Zero results in a crash.

Frequently Asked Questions

Want to get errata notifications? Sign up here.