CVE-2026-10118: Red Hat Ai Inference Server 3.3
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
Affected products
- Red Hat Red Hat Ai Inference Server 3.3: before 1782352950 (fixed in 1782352950); before 1782352919 (fixed in 1782352919); before 1782353093 (fixed in 1782353093); before 1782352847 (fixed in 1782352847)
- Red Hat Red Hat Enterprise Linux 10: before 0:24.02.0-7.el10_2.2 (fixed in 0:24.02.0-7.el10_2.2)
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:24.02.0-7.el10_0.1 (fixed in 0:24.02.0-7.el10_0.1)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:0.22.5-7.el7_9 (fixed in 0:0.22.5-7.el7_9); before 0:0.26.5-44.el7_9 (fixed in 0:0.26.5-44.el7_9)
- Red Hat Red Hat Enterprise Linux 8: before 0:20.11.0-14.el8_10 (fixed in 0:20.11.0-14.el8_10)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:20.11.0-2.el8_4.3 (fixed in 0:20.11.0-2.el8_4.3)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:20.11.0-2.el8_4.3 (fixed in 0:20.11.0-2.el8_4.3)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:20.11.0-5.el8_6.1 (fixed in 0:20.11.0-5.el8_6.1)
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 0:20.11.0-5.el8_6.1 (fixed in 0:20.11.0-5.el8_6.1)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:20.11.0-7.el8_8.1 (fixed in 0:20.11.0-7.el8_8.1)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:20.11.0-7.el8_8.1 (fixed in 0:20.11.0-7.el8_8.1)
- Red Hat Red Hat Enterprise Linux 9: before 0:21.01.0-24.el9_8.1 (fixed in 0:21.01.0-24.el9_8.1)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:21.01.0-15.el9_2.1 (fixed in 0:21.01.0-15.el9_2.1)
- Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:21.01.0-20.el9_4.1 (fixed in 0:21.01.0-20.el9_4.1)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:21.01.0-22.el9_6.1 (fixed in 0:21.01.0-22.el9_6.1)
- Red Hat Red Hat Hardened Images: before 26.06.0-0.1.hum1 (fixed in 26.06.0-0.1.hum1)
- Red Hat Red Hat Openshift Ai 3.4: before 1790703542 (fixed in 1790703542)
Published 2026-06-01. Last modified 2026-10-02.