Debian 11023 Published by

Debian released ELA-1791-1 and ELA-1792-1 to patch critical security flaws in OpenJDK 8 version 8u502-ga-1~deb9u1 and Poppler across stretch and buster distributions. The Java runtime update addresses ten vulnerabilities that could enable denial of service attacks, unauthorized data access, or sandbox restriction bypasses. Poppler patches six PDF processing flaws, including signature forgery risks, infinite recursion crashes, use-after-free memory corruption, and integer overflow errors that enable arbitrary code execution.

ELA-1791-1 openjdk-8 security update (by )
ELA-1792-1 poppler security update (by )




ELA-1791-1 openjdk-8 security update (by )


Package : openjdk-8

Version : 8u502-ga-1~deb9u1 (stretch)

Related CVEs :
CVE-2026-41254
CVE-2026-46968
CVE-2026-47010
CVE-2026-47021
CVE-2026-47027
CVE-2026-47057
CVE-2026-47058
CVE-2026-47059
CVE-2026-47063
CVE-2026-60147

Several vulnerabilities have been discovered in the OpenJDK Java
runtime, which may result in denial of service, information disclosure
or bypass of sandbox restrictions.


ELA-1791-1 openjdk-8 security update (by )



ELA-1792-1 poppler security update (by )


Package : poppler

Version : 0.48.0-2+deb9u8 (stretch), 0.71.0-5+deb10u5 (buster)

Related CVEs :
CVE-2025-43718
CVE-2025-43903
CVE-2025-50420
CVE-2025-52885
CVE-2025-52886
CVE-2026-10118

CVE-2025-43718

It was discovered that crafted PDF files containing deeply nested
structures within the metadata could lead to Denial of Service.
(This issue did not affect the poppler version found in Debian
stretch.)

CVE-2025-43903

It was discovered signatures with non-empty encapsulated content
(typically adbe.pkcs7.sha1) were not correctly verified, thereby
allowing trivial signature forgery.

CVE-2025-50420

An infinite recursion issue was discovered in the
pdfseparate(1)
utility, which may cause denial of service via crafted PDF input
file.

CVE-2025-52885

Antonio Morales discovered a use-after-free issue, which may lead to
arbitrary code execution via crafted PDF input files.
(This issue did not affect the poppler version found in Debian
stretch.)

CVE-2025-52886

Kevin Backhouse discovered an integer overflow issue, which may lead
to use-after-free via crafted PDF input file.

CVE-2026-10118

An integer overflow issue was discovered in tilingPatternFill(),
which may lead to arbitrary code execution via crafted PDF input
files.


ELA-1792-1 poppler security update (by )