Stack Buffer Overflow in SumatraPDF Affects Windows Users
CVE-2026-107736

6.8MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107736?

A stack buffer overflow vulnerability exists in SumatraPDF, a multi-format reader for Windows, that affects versions 3.6.1 and earlier. The issue is triggered when the MaybeFlipBitmap() function attempts to read an attacker-controlled PropertyTagOrientation size using GetPropertyItem() while only providing a fixed 64-byte buffer on the stack. When a specially crafted TIFF image containing excessive EXIF Orientation values is opened, it can lead to the overwriting of stack control data by specific attacker-chosen bytes. Although tested builds reportedly terminate due to stack cookie verification, the potential for exploitation remains under the conditions outlined. No patched version has been released at the time of this review.

Affected Version(s)

sumatrapdf <= 3.6.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.