evince-40.5-4.el9_8.1

エラータID: AXSA:2026-1365:02

Release date: 
Tuesday, July 28, 2026 - 14:08
Subject: 
evince-40.5-4.el9_8.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The evince packages provide a simple multi-page document viewer for Portable Document Format (PDF), PostScript (PS), Encapsulated PostScript (EPS) files, and, with additional back-ends, also the Device Independent File format (DVI) files.

Security Fix(es):

* atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen (CVE-2026-46529)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-46529
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT `--checkpoint-action` injection in `comics-document.c`, fixed in 1.6.2) but in a different code path (`shell/ev-application.c`) that the original patch did not touch.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. evince-40.5-4.el9_8.1.src.rpm
    MD5: 544d0317feba096938796d71e252dd65
    SHA-256: cc1d4b91c0e4b63045f2c97fd34a1807eb9b4b0fd62d8bc477c6c4955ca7ca02
    Size: 2.82 MB

Asianux Server 9 for x86_64
  1. evince-40.5-4.el9_8.1.x86_64.rpm
    MD5: cd2463e59cafe606af2041b3c2b9ff1d
    SHA-256: bf07da46348c63f511f34ddfb13f822bc1f393fbad5bc39a211003484c294598
    Size: 2.09 MB
  2. evince-libs-40.5-4.el9_8.1.i686.rpm
    MD5: f7f061ee32bbc09508b5fb11f29bef13
    SHA-256: d4dac9379b4a3235f3aa43fec9586a293270925ff622b612115458a2c4545d05
    Size: 401.45 kB
  3. evince-libs-40.5-4.el9_8.1.x86_64.rpm
    MD5: 11a2654eb742382c6b548843bb60c50e
    SHA-256: 81ed4dcbf128e43af772b71183bf3c2626f0c9245f4612b87a8d5ce7ab667acd
    Size: 375.33 kB
  4. evince-nautilus-40.5-4.el9_8.1.x86_64.rpm
    MD5: fc7b53c829fce746c68ca303ffeb3f76
    SHA-256: ce2331d26aca76531dd8ded3ca54bd149a02f75d1c7d93c12ba19f13a51e8919
    Size: 16.13 kB
  5. evince-previewer-40.5-4.el9_8.1.x86_64.rpm
    MD5: 60616ff12e88071b1f66f9e4d1c7a0fb
    SHA-256: ed34cfbf4e835dfc62784544e2dc2fbf98f138f3f26a735347fe2462f4dd676b
    Size: 24.37 kB
  6. evince-thumbnailer-40.5-4.el9_8.1.x86_64.rpm
    MD5: 0afa3153eec2a52b7093958f08fcc277
    SHA-256: 1838de3922ad92e2beebc5c65748006558b279d26914b7b3c80c813944a85d69
    Size: 14.56 kB