PT-2026-79059 · Unknown · Sumatrapdf

CVE-2026-55586

·

Published

2026-06-14

·

Updated

2026-08-21

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions SumatraPDF versions prior to 3.6.2
Description A crafted CHM file can provide malformed LZX Huffman code lengths to the make decode table function in ext/CHMLib/lzx.c. In the long-code branch, the function writes new internal nodes via next symbol before validating if the canonical Huffman table has overflowed. Specifically, the PRETREE case can write beyond the 104-entry PRETREE table into the adjacent heap state in struct LZXstate when accessed through the sequence of chm open, chm retrieve object, LZXdecompress, and BUILD TABLE. This results in heap memory corruption within the parser process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12656
CVE-2026-55586
GHSA-M423-RP8P-WHJ8

Affected Products

Sumatrapdf