PT-2026-108290 · Sumatrapdfreader · Sumatrapdf
CVE-2026-107729
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, src/MobiDoc.cpp narrows the untrusted unsigned mobiHdr.hdrLen field to a signed integer for validation; values above INT MAX become negative and bypass the upper-bound check. When the EXTH flag is set, the original unsigned value is reused as a pointer offset, causing DecodeExthHeader() to read beyond the record buffer. Opening a crafted MOBI file can reliably terminate the application with a native access violation; no code execution, information disclosure, or integrity impact has been demonstrated. No fixed version is available as of this review.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sumatrapdf