yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2025-32365
Component Overview
Vulnerability Overview
Name
CVE-2025-32365
Source
NVD (
link
)
Debian (
link
)
Description
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
CWEs
CWE-125
Published Date
Apr 5, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gitlab.freedesktop.org/poppler/poppler/-/issues/1577
Exploit
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/1792
Product
Analysis
#
Affected Component
Analysis
poppler
Patched
Vulnerability Ratings
#
4
CVSSv31
7.1
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
poppler
buildroot
2025.02.x
25.10.0
Not Affected
poppler
buildroot
master
25.10.0
Not Affected
poppler
yocto
master
25.12.0
Not Affected
poppler
yocto
scarthgap
23.04.0
Patched
Resolved with patches
#
poppler (yocto:kirkstone)
#
Title
Author
Resolve
1
Move isOk check to inside JBIG2Bitmap::combine
Albert Astals Cid <aacid@kde.org>
CVE-2025-32365
poppler (yocto:scarthgap)
#
Title
Author
Resolve
1
Move isOk check to inside JBIG2Bitmap::combine
Albert Astals Cid <aacid@kde.org>
CVE-2025-32365