yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-56378
Component Overview
Vulnerability Overview
Name
CVE-2024-56378
Source
NVD (
link
)
Debian (
link
)
Description
libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.
CWEs
CWE-125
Published Date
Dec 23, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gitlab.freedesktop.org/poppler/poppler/-/blob/30eada0d2bceb42c2d2a87361339063e0b9bea50/CMakeLists.txt#L621
Product
https://gitlab.freedesktop.org/poppler/poppler/-/commit/ade9b5ebed44b0c15522c27669ef6cdf93eff84e
Patch
https://gitlab.freedesktop.org/poppler/poppler/-/issues/1553
Exploit
Analysis
#
Affected Component
Analysis
poppler
Patched
Vulnerability Ratings
#
4.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
poppler
buildroot
2025.02.x
25.10.0
Not Affected
poppler
buildroot
master
25.10.0
Not Affected
poppler
yocto
master
25.12.0
Not Affected
poppler
yocto
scarthgap
23.04.0
Patched
Resolved with patches
#
poppler (yocto:kirkstone)
#
Title
Author
Resolve
1
JBIG2Bitmap::combine: Fix crash on malformed files
Albert Astals Cid <aacid@kde.org>
CVE-2024-56378
poppler (yocto:scarthgap)
#
Title
Author
Resolve
1
JBIG2Bitmap::combine: Fix crash on malformed files
Albert Astals Cid <aacid@kde.org>
CVE-2024-56378