PT-2026-79059 · Unknown · Sumatrapdf
CVE-2026-55586
·
Published
2026-06-14
·
Updated
2026-08-21
CVSS v3.1
6.6
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
SumatraPDF versions prior to 3.6.2
Description
A crafted CHM file can provide malformed LZX Huffman code lengths to the
make decode table function in ext/CHMLib/lzx.c. In the long-code branch, the function writes new internal nodes via next symbol before validating if the canonical Huffman table has overflowed. Specifically, the PRETREE case can write beyond the 104-entry PRETREE table into the adjacent heap state in struct LZXstate when accessed through the sequence of chm open, chm retrieve object, LZXdecompress, and BUILD TABLE. This results in heap memory corruption within the parser process.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sumatrapdf