Highlights
Memory Corruption: 74 prior fixes. Scrutinize any change in this area.
poppler/JBIG2Stream.cc: most-fixed (55 issues). Treat as high-risk during review.
157 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Integer Overflow: Dominant vulnerability class with dozens of fixes in JBIG2 decoding, where unchecked arithmetic on dimensions, coordinates, and symbol counts leads to heap overflows and out-of-bounds access.
Memory Corruption: Numerous fixes for out-of-bounds reads/writes, use-after-free, double-free, and null dereferences in JBIG2 bitmap combining, symbol dictionary handling, and MMR decoding, often stemming from missing bounds checks and improper memory management.
Use After Free: Signature validation code has multiple use-after-free and double-free bugs from manual NSS memory management, including freeing unowned certificates and mismatched alloc/dealloc.