Bug 2400893 (CVE-2025-43718) - CVE-2025-43718 poppler: Poppler stack overflow
Summary: CVE-2025-43718 poppler: Poppler stack overflow
Keywords:
Status: NEW
Alias: CVE-2025-43718
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2401096 2401098 2401095 2401097
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-10-01 20:02 UTC by OSIDB Bzimport
Modified: 2025-10-02 17:58 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-10-01 20:02:53 UTC
Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Dict::lookup, Catalog::getMetadata, and associated functions in PDFDoc, with deep recursion in the regex executor (std::__detail::_Executor).


Note You need to log in before you can comment on or make changes to this bug.