evince-40.5-4.el9_8.1
エラータID: AXSA:2026-1365:02
The evince packages provide a simple multi-page document viewer for Portable Document Format (PDF), PostScript (PS), Encapsulated PostScript (EPS) files, and, with additional back-ends, also the Device Independent File format (DVI) files.
Security Fix(es):
* atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen (CVE-2026-46529)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-46529
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT `--checkpoint-action` injection in `comics-document.c`, fixed in 1.6.2) but in a different code path (`shell/ev-application.c`) that the original patch did not touch.
Update packages.
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT `--checkpoint-action` injection in `comics-document.c`, fixed in 1.6.2) but in a different code path (`shell/ev-application.c`) that the original patch did not touch.
N/A
SRPMS
- evince-40.5-4.el9_8.1.src.rpm
MD5: 544d0317feba096938796d71e252dd65
SHA-256: cc1d4b91c0e4b63045f2c97fd34a1807eb9b4b0fd62d8bc477c6c4955ca7ca02
Size: 2.82 MB
Asianux Server 9 for x86_64
- evince-40.5-4.el9_8.1.x86_64.rpm
MD5: cd2463e59cafe606af2041b3c2b9ff1d
SHA-256: bf07da46348c63f511f34ddfb13f822bc1f393fbad5bc39a211003484c294598
Size: 2.09 MB - evince-libs-40.5-4.el9_8.1.i686.rpm
MD5: f7f061ee32bbc09508b5fb11f29bef13
SHA-256: d4dac9379b4a3235f3aa43fec9586a293270925ff622b612115458a2c4545d05
Size: 401.45 kB - evince-libs-40.5-4.el9_8.1.x86_64.rpm
MD5: 11a2654eb742382c6b548843bb60c50e
SHA-256: 81ed4dcbf128e43af772b71183bf3c2626f0c9245f4612b87a8d5ce7ab667acd
Size: 375.33 kB - evince-nautilus-40.5-4.el9_8.1.x86_64.rpm
MD5: fc7b53c829fce746c68ca303ffeb3f76
SHA-256: ce2331d26aca76531dd8ded3ca54bd149a02f75d1c7d93c12ba19f13a51e8919
Size: 16.13 kB - evince-previewer-40.5-4.el9_8.1.x86_64.rpm
MD5: 60616ff12e88071b1f66f9e4d1c7a0fb
SHA-256: ed34cfbf4e835dfc62784544e2dc2fbf98f138f3f26a735347fe2462f4dd676b
Size: 24.37 kB - evince-thumbnailer-40.5-4.el9_8.1.x86_64.rpm
MD5: 0afa3153eec2a52b7093958f08fcc277
SHA-256: 1838de3922ad92e2beebc5c65748006558b279d26914b7b3c80c813944a85d69
Size: 14.56 kB