Integer Overflow Vulnerability in SumatraPDF Multi-Format Reader
CVE-2026-107729

5.5MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107729?

SumatraPDF, a versatile multi-format reader for Windows, has an integer overflow vulnerability in version 3.7.0.22298. This issue stems from the narrowing of the unsigned 'mobiHdr.hdrLen' to a signed integer type for validation within the src/MobiDoc.cpp file. Consequently, any values exceeding INT_MAX are treated as negative, which allows an unintended bypass of the upper-bound check. When the EXTH flag is activated, the flawed handling enables the original unsigned value to be erroneously used as a pointer offset. This mismanagement may cause the DecodeExthHeader() function to attempt reading beyond the designated record buffer. While this issue can reliably lead to the termination of the application due to a native access violation when a specially crafted MOBI file is opened, no evidence exists of code execution, information disclosure, or integrity compromise tied to this vulnerability. At present, there is no available patch to rectify this vulnerability.

Affected Version(s)

sumatrapdf <= 3.7.0.22298

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.