Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an att…
High CVSS 7.8
Summary
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-inde…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/mate-desktop/atril/releases/tag/v1.26.3
- https://github.com/mate-desktop/atril/releases/tag/v1.28.4
- https://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f
- http://www.openwall.com/lists/oss-security/2026/05/19/34
- http://www.openwall.com/lists/oss-security/2026/05/21/7
- http://www.openwall.com/lists/oss-security/2026/05/22/11
- https://lists.debian.org/debian-lts-announce/2026/05/msg00041.html
- https://lists.debian.org/debian-lts-announce/2026/05/msg00042.html
- https://lists.debian.org/debian-lts-announce/2026/06/msg00021.html
- https://access.redhat.com/errata/RHSA-2026:27819
- https://access.redhat.com/errata/RHSA-2026:28998
- https://access.redhat.com/errata/RHSA-2026:33169
- https://access.redhat.com/errata/RHSA-2026:33416
- https://access.redhat.com/errata/RHSA-2026:39115
- https://access.redhat.com/errata/RHSA-2026:41904
- https://access.redhat.com/errata/RHSA-2026:42692
- https://access.redhat.com/security/cve/CVE-2026-46529
- https://bugzilla.redhat.com/show_bug.cgi?id=2487669
- https://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46529.json
Timeline
- nvd_ingest NVD