Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.
https://www.debian.org/security/2022/dsa-5224
https://www.cve.org/CVERecord?id=CVE-2022-38171
https://security.gentoo.org/glsa/202209-21
https://poppler.freedesktop.org/releases.html
https://lists.debian.org/debian-lts-announce/2022/09/msg00030.html
https://github.com/zmanion/Vulnerabilities/blob/main/CVE-2022-38171.md