PT-2026-61819 · Gnome+1 · Evince+1

·

CVE-2026-63729

·

Published

2026-07-21

·

Updated

2026-09-02

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TeX Live (affected versions not specified) GNOME Evince (affected versions not specified)
Description The SyncTeX parser (synctex parser.c) contains a heap use-after-free issue. This occurs when a malformed .synctex or .synctex.gz file constructs a ref node with a NULL parent pointer. This causes the replacement routine to fail to detach the node from its sibling chain, triggering recursive freeing of live tree nodes and leaving dangling pointers that the parser accesses during document load. This can lead to application crashes or potential arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63729
ECHO-29B4-3924-6ADF
OESA-2026-3192
OPENSUSE-SU-2026:11412-1
SUSE-SU-2026:3512-1
SUSE-SU-2026:3628-1
SUSE-SU-2026:3924-1

Affected Products

Evince
Tex Live