- What: Security update for evince in Red Hat
- Impact: Addresses vulnerabilities in the document viewer
Red Hat Product Errata RHSA-2026:43398 - Security Advisory Issued: 2026-07-22 Updated: 2026-07-22 RHSA-2026:43398 - Security Advisory Overview Updated Packages Synopsis Important: evince security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for evince is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The evince packages provide a simple multi-page document viewer for Portable Document Format (PDF), PostScript (PS), Encapsulated PostScript (EPS) files, and, with additional back-ends, also the Device Independent File format (DVI) files. Security Fix(es): atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen (CVE-2026-46529) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2487669 - CVE-2026-46529 atril: evince: xreader: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen CVEs CVE-2026-46529 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 SRPM evince-3.28.4-11.el8_4.1.src.rpm SHA-256: c19a556b6d7e6faf27d323d89a611b4b9f94ccede734e090727357e7e4ee8879 x86_64 evince-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 48db67b3835c76e48172ec8ba29ee9a80201adf06626e278be29c5cd27e6d4c3 evince-browser-plugin-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: e6b962055228fdc48138e86faea7602d7a3bf83300c7c059307ddd9cbde7b5ac evince-browser-plugin-debuginfo-3.28.4-11.el8_4.1.i686.rpm SHA-256: 9794c4e81e7ac8763724326bc80712e1d82c6e3ac12442c9ca5f5c673bcaa7c7 evince-browser-plugin-debuginfo-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 9fdbc6b0d272051029db0399ffb6c5757621947d1672f0bcde3afce224f3d0cb evince-debuginfo-3.28.4-11.el8_4.1.i686.rpm SHA-256: d0518ef58443eaa533d81ffbbb94764fe852d74ffc25b3fb6beab43731f946fe evince-debuginfo-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: d4930639615188c0e61d689ea968225d023a12fa6863a07511b253f1b0fd169a evince-debugsource-3.28.4-11.el8_4.1.i686.rpm SHA-256: 3de2c6228e08382461189f23d5975a96678d650f7ee37ab726fe4ecd2911891c evince-debugsource-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 8d3161a9b341f4ad3e7169c5c507e5a77f62bafc9099226ed556e57bfab1f405 evince-libs-3.28.4-11.el8_4.1.i686.rpm SHA-256: 399faea8c47d3139031ff9084724355a6675b1f9aa873dfffd1d1d0fb0134eee evince-libs-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: d131ae420c91cac70705acda4757f4fb38cc4e613b221a4d10ce900697804239 evince-libs-debuginfo-3.28.4-11.el8_4.1.i686.rpm SHA-256: 16d31ecca6e6ab9eb6271adafd91dcedaaf021f58ce875a88cfab1d2f158d47f evince-libs-debuginfo-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 30079730c41ffd5f031268785e52e4fcd114da2d15d0b0f4d0fe07f863fb173b evince-nautilus-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 2fad078f20ff41984b0c045eece8e33bb1be58842fb52bd271c63b427e12b716 evince-nautilus-debuginfo-3.28.4-11.el8_4.1.i686.rpm SHA-256: fc1c90b81ff21a0b7dd133055a4f995d5b7f852870854060bfb24402745dacdd evince-nautilus-debuginfo-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 58375ca7bdf80a68a1a9e294960e7af62cdf1ab739c6d193f2570e4394e47188 Red Hat Enterprise Linux Server - AUS 8.4 SRPM evince-3.28.4-11.el8_4.1.src.rpm SHA-256: c19a556b6d7e6faf27d323d89a611b4b9f94ccede734e090727357e7e4ee8879 x86_64 evince-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 48db67b3835c76e48172ec8ba29ee9a80201adf06626e278be29c5cd27e6d4c3 evince-browser-plugin-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: e6b962055228fdc48138e86faea7602d7a3bf83300c7c059307ddd9cbde7b5ac evince-browser-plugin-debuginfo-3.28.4-11.el8_4.1.i686.rpm SHA-256: 9794c4e81e7ac8763724326bc80712e1d82c6e3ac12442c9ca5f5c673bcaa7c7 evince-browser-plugin-debuginfo-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 9fdbc6b0d272051029db0399ffb6c5757621947d1672f0bcde3afce224f3d0cb evince-debuginfo-3.28.4-11.el8_4.1.i686.rpm SHA-256: d0518ef58443eaa533d81ffbbb94764fe852d74ffc25b3fb6beab43731f946fe evince-debuginfo-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: d4930639615188c0e61d689ea968225d023a12fa6863a07511b253f1b0fd169a evince-debugsource-3.28.4-11.el8_4.1.i686.rpm SHA-256: 3de2c6228e08382461189f23d5975a96678d650f7ee37ab726fe4ecd2911891c evince-debugsource-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 8d3161a9b341f4ad3e7169c5c507e5a77f62bafc9099226ed556e57bfab1f405 evince-libs-3.28.4-11.el8_4.1.i686.rpm SHA-256: 399faea8c47d3139031ff9084724355a6675b1f9aa873dfffd1d1d0fb0134eee evince-libs-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: d131ae420c91cac70705acda4757f4fb38cc4e613b221a4d10ce900697804239 evince-libs-debuginfo-3.28.4-11.el8_4.1.i686.rpm SHA-256: 16d31ecca6e6ab9eb6271adafd91dcedaaf021f58ce875a88cfab1d2f158d47f evince-libs-debuginfo-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 30079730c41ffd5f031268785e52e4fcd114da2d15d0b0f4d0fe07f863fb173b evince-nautilus-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 2fad078f20ff41984b0c045eece8e33bb1be58842fb52bd271c63b427e12b716 evince-nautilus-debuginfo-3.28.4-11.el8_4.1.i686.rpm SHA-256: fc1c90b81ff21a0b7dd133055a4f995d5b7f852870854060bfb24402745dacdd evince-nautilus-debuginfo-3.28.4-11.el8_4.1.x86_64.rpm SHA-256: 58375ca7bdf80a68a1a9e294960e7af62cdf1ab739c6d193f2570e4394e47188 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .