DigiNews

Tech Watch by Johan Denoyer

← Back to articles

CVE-2026-46529: 10-year-old RCE in Linux PDF Viewer (XReader/Evince/Atril)

Quality: 8/10 Relevance: 9/10

Summary

The article provides a detailed vulnerability write-up of CVE-2026-46529 affecting Evince/Atril, describing how unquoted CLI arguments and GTK module handling enable RCE, including a polyglot PDF/ELF technique. It references sources and advisories.

🚀 Service construit par Johan Denoyer