Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:27819: Important: evince security update

A critical vulnerability (CVE-2026-46529) in the evince document viewer allows for single-click remote code execution via an argument injection flaw in PDF /GoToR actions, which can be exploited to load arbitrary GTK modules. The Red Hat advisory rates this update as Important, but the specific CVSS score and affected version ranges for the evince packages are not detailed within the provided text. The fix is delivered via updated packages for Red Hat Enterprise Linux 9, and administrators should apply the referenced security update to all affected systems.
Read Full Article →

Red Hat Product Errata RHSA-2026:27819 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:27819 - Security Advisory Overview Updated Packages Synopsis Important: evince security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for evince is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The evince packages provide a simple multi-page document viewer for Portable Document Format (PDF), PostScript (PS), Encapsulated PostScript (EPS) files, and, with additional back-ends, also the Device Independent File format (DVI) files. Security Fix(es): atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen (CVE-2026-46529) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2487669 - CVE-2026-46529 atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen CVEs CVE-2026-46529 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM evince-40.5-4.el9_8.1.src.rpm SHA-256: f146c83e84360706a3ebc2759c3985f69bfa912633b8cdcd43c79b8c15dc7c8f x86_64 evince-40.5-4.el9_8.1.x86_64.rpm SHA-256: a01b7f8f6f3d11b30a411ec05aa2362236ead882fc66715aa82b2972228c7080 evince-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: b1411a79b1fe4cb504f3e94737060ba7fcae06b12d729aaa1443594448483d04 evince-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: 6081e9e7575569d17a71518d7dfd823d644686ac5641c9891e8f3ee3328f77dc evince-debugsource-40.5-4.el9_8.1.i686.rpm SHA-256: 28cee12b8cb8a1133dc213a8d9b140f641f07330cb3c977021a1cbbda71d212d evince-debugsource-40.5-4.el9_8.1.x86_64.rpm SHA-256: c8d295b5e1377e2d3472561fddc49a927674ab6143496b3a29a05b34b659548b evince-dvi-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: e1ab6e7aa389f252e6dc26fb9b3c9ec6aba601d2eaa08f39687289c1dbcec187 evince-dvi-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: 3934c6476df579fd94216f9bc36a4c0e2685a354a9f77e5e17591cc7f84ec574 evince-libs-40.5-4.el9_8.1.i686.rpm SHA-256: f755283c26df354af38136c558013e518e4240173131876054f22e1019ee3ed0 evince-libs-40.5-4.el9_8.1.x86_64.rpm SHA-256: f29622e346687d12c66f53e4574f8ff3094a925ea823dcac5ae4cbfc79f0c99a evince-libs-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: dd00475187d6d87af480e73b22b5d5f51cfa2efba7cb8114b4d7213d08feb3c9 evince-libs-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: eeb1d10276dbe12cb0624e9c9c8b09b5867ef1fb343e55d58127ab729ea591cf evince-nautilus-40.5-4.el9_8.1.x86_64.rpm SHA-256: f1f8fb1ff1119a5644e225e3d8d99d3ea1278935fb50656f371b880cd2df1bfc evince-nautilus-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: 0a8d2934b1395a796b1d419279429c67d5b6f5c66692ac2cf7068a102b84aba1 evince-nautilus-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: 191e941ae324237ad09a78588aa78f074a7384785c7210e293367691e40c3dfb evince-previewer-40.5-4.el9_8.1.x86_64.rpm SHA-256: 24fa40e5fa5f66a06740a0ce153b333dddefb25b655faca0ca5c63c7e2766d8d evince-previewer-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: f19b069794538f21631917cd92f18b8ee0a5fe86e854766f56f341293a161323 evince-previewer-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: 789b1176ad6ae029af76fc51db33cf289d7b13fe4fb9253e23acebbf2283640f evince-thumbnailer-40.5-4.el9_8.1.x86_64.rpm SHA-256: 23c6c34ce7a3c8ac2dfb9ce585765e134e7e40dd41ec126025d04c2d69a7b247 evince-thumbnailer-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: 913c833d1873e672587ffb744697b4e3bbd9361f7371ed3ec903dc1a2a21e169 evince-thumbnailer-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: 0615fef4fa3810e13b821fd2ba9045f242eb0d56d894ea9e0929689006bf9d28 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM evince-40.5-4.el9_8.1.src.rpm SHA-256: f146c83e84360706a3ebc2759c3985f69bfa912633b8cdcd43c79b8c15dc7c8f x86_64 evince-40.5-4.el9_8.1.x86_64.rpm SHA-256: a01b7f8f6f3d11b30a411ec05aa2362236ead882fc66715aa82b2972228c7080 evince-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: b1411a79b1fe4cb504f3e94737060ba7fcae06b12d729aaa1443594448483d04 evince-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: 6081e9e7575569d17a71518d7dfd823d644686ac5641c9891e8f3ee3328f77dc evince-debugsource-40.5-4.el9_8.1.i686.rpm SHA-256: 28cee12b8cb8a1133dc213a8d9b140f641f07330cb3c977021a1cbbda71d212d evince-debugsource-40.5-4.el9_8.1.x86_64.rpm SHA-256: c8d295b5e1377e2d3472561fddc49a927674ab6143496b3a29a05b34b659548b evince-dvi-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: e1ab6e7aa389f252e6dc26fb9b3c9ec6aba601d2eaa08f39687289c1dbcec187 evince-dvi-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: 3934c6476df579fd94216f9bc36a4c0e2685a354a9f77e5e17591cc7f84ec574 evince-libs-40.5-4.el9_8.1.i686.rpm SHA-256: f755283c26df354af38136c558013e518e4240173131876054f22e1019ee3ed0 evince-libs-40.5-4.el9_8.1.x86_64.rpm SHA-256: f29622e346687d12c66f53e4574f8ff3094a925ea823dcac5ae4cbfc79f0c99a evince-libs-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: dd00475187d6d87af480e73b22b5d5f51cfa2efba7cb8114b4d7213d08feb3c9 evince-libs-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: eeb1d10276dbe12cb0624e9c9c8b09b5867ef1fb343e55d58127ab729ea591cf evince-nautilus-40.5-4.el9_8.1.x86_64.rpm SHA-256: f1f8fb1ff1119a5644e225e3d8d99d3ea1278935fb50656f371b880cd2df1bfc evince-nautilus-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: 0a8d2934b1395a796b1d419279429c67d5b6f5c66692ac2cf7068a102b84aba1 evince-nautilus-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: 191e941ae324237ad09a78588aa78f074a7384785c7210e293367691e40c3dfb evince-previewer-40.5-4.el9_8.1.x86_64.rpm SHA-256: 24fa40e5fa5f66a06740a0ce153b333dddefb25b655faca0ca5c63c7e2766d8d evince-previewer-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: f19b069794538f21631917cd92f18b8ee0a5fe86e854766f56f341293a161323 evince-previewer-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: 789b1176ad6ae029af76fc51db33cf289d7b13fe4fb9253e23acebbf2283640f evince-thumbnailer-40.5-4.el9_8.1.x86_64.rpm SHA-256: 23c6c34ce7a3c8ac2dfb9ce585765e134e7e40dd41ec126025d04c2d69a7b247 evince-thumbnailer-debuginfo-40.5-4.el9_8.1.i686.rpm SHA-256: 913c833d1873e672587ffb744697b4e3bbd9361f7371ed3ec903dc1a2a21e169 evince-thumbnailer-debuginfo-40.5-4.el9_8.1.x86_64.rpm SHA-256: 0615fef4fa3810e13b821fd2ba9045f242eb0d56d894ea9e0929689006bf9d28 Red Hat Enterprise Linux for IBM z Systems 9 SRPM evince-40.5-4.el9_8.1.src.rpm SHA-256: f146c83e84360706a3ebc2759c3985f69bfa912633b8cdcd43c79b8c15dc7c8f s390x evince-40.5-4.el9_8.1.s390x.rpm SHA-256: f7ff821db0471a9c41c7c1f93d8989ffb7e3c9b53f2ed4ac4d7789e9254583cb evince-debuginfo-40.5-4.el9_8.1.s390x.rpm SHA-256: 3220f78daba6d9d119ef55f80275a9b39f77a773de868aea2a640010559e9b93 evince-debugsource-40.5-4.el9_8.1.s390x.rpm SHA-256: 4721bc491478d50934176ae2e508cc1ca81a06da5d2b4fa409e499a0216669ac evince-dvi-debuginfo-40.5-4.el9_8.1.s390x.rpm SHA-256: 3064e026f566e907139cd4b0419fb7df9b86e6a5b98f2d57e4cf0be2bcc6d9a9 evince-libs-40.5-4.el9_8.1.s390x.rpm SHA-256: 29b2668ce2ead331b45a7e7ec7a1ea0f7dacfc39c78bf5e21292331b1bd6b082 evince-libs-debuginfo-40.5-4.el9_8.1.s390x.rpm SHA-256: ff43f72b216c9dd2c2a01cf2f8922762653b12bb1867fbf911da0229bf6ed508 evince-nautilus-40.5-4.el9_8.1.s390x.rpm SHA-256: 241ca517e65f4aa0f942abcb72cc9e813a2fa261c94b16e93907d741892cf8df evince-nautilus-debuginfo-40.5-4.el9_8.1.s390x.rpm SHA-256: c9f914135359c0ae7e01f794a3f90302ab71d8dd6fb7906717f8e08e8b1db265 evince-previewer-40.5-4.el9_8.1.s390x.rpm SHA-256: c8e25363803e576d2a34347cec6e5731f35627308aae7c874d6b7a99572ce621 evince-previewer-debuginfo-40.5-4.el9_8.1.s390x.rpm SHA-256: c32e8f81061082a77ebf5054adffdbfefa10b309fe36095d1db71c8e8d03ef3a evince-thumbnailer-40.5-4.el9_8.1.s390x.rpm SHA-256: 53d83ebc3d6c4f8883939c78abc14a2087b1af509a5f98c6cf7b456bf96151f0 evince-thumbnailer-debuginfo-40.5-4.el9_8.1.s390x.rpm SHA-256: 8f5f3af06754081e9f90672885e468dbc88d049f73dc27c2939266a9c01a4a50 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 SRPM evince-40.5-4.el9_8.1.src.rpm SHA-256: f146c83e84360706a3ebc2759c3985f69bfa912633b8cdcd43c79b8c15dc7c8f s390x evince-40.5-4.el9_8.1.s390x.rpm SHA-256: f7ff821db0471a9c41c7c1f93d8989ffb7e3c9b53f2ed4ac4d7789e9254583cb evince-debuginfo-40.5-4.el9_8.1.s390x.rpm SHA-256: 3220f78daba6d9d119ef55f

Share this article