CVE-2026-38076 is an integer overflow vulnerability in the jbig2_arith_iaid_ctx_new() function of Artifex software. The vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. The CVSS score for this vulnerability is 7.5, indicating a high severity level. Affected product deployments should be identified, and owners assigned for follow-up. Official advisories and CVE records [truncated]
MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. This can lead to a double-free error when the caller also drops the same pixmap in cleanup, potentially corrupting the heap and crashing the process. Developers and users of MuPDF library, especially those who enable and use MuPDF barcode de [truncated]