vulnerability

SUSE: CVE-2025-52885: SUSE Linux Security Advisory

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Oct 24, 2025
Added
Dec 5, 2025
Modified
Dec 10, 2025

Description

Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulnerability has been detected in versions Poppler prior to 25.10.0 within the StructTreeRoot class. The issue arises from the use of raw pointers to elements of a `std::vector`, which can lead to dangling pointers when the vector is resized. The vulnerability stems from the way that refToParentMap stores references to `std::vector` elements using raw pointers. These pointers may become invalid when the vector is resized. This vulnerability is a common security problem involving the use of raw pointers to `std::vectors`. Internally, `std::vector `stores its elements in a dynamically allocated array. When the array reaches its capacity and a new element is added, the vector reallocates a larger block of memory and moves all the existing elements to the new location. At this point if any pointers to elements are stored before a resize occurs, they become dangling pointers once the reallocation happens. Version 25.10.0 contains a patch for the issue.

Solutions

suse-upgrade-libpoppler-cpp0suse-upgrade-libpoppler-cpp0-32bitsuse-upgrade-libpoppler-develsuse-upgrade-libpoppler-glib-develsuse-upgrade-libpoppler-glib8suse-upgrade-libpoppler-glib8-32bitsuse-upgrade-libpoppler-qt5-1suse-upgrade-libpoppler-qt5-1-32bitsuse-upgrade-libpoppler-qt5-develsuse-upgrade-libpoppler-qt6-3suse-upgrade-libpoppler-qt6-develsuse-upgrade-libpoppler126suse-upgrade-libpoppler135suse-upgrade-libpoppler135-32bitsuse-upgrade-libpoppler89suse-upgrade-poppler-toolssuse-upgrade-typelib-1_0-poppler-0_18
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.