Heap Out-of-Bounds Read Vulnerability in SumatraPDF by SumatraPDF Reader
CVE-2026-25920
What is CVE-2026-25920?
A heap out-of-bounds read vulnerability has been identified in SumatraPDF, a widely-used multi-format reader for Windows. This issue resides in the MOBI HuffDic decompressor, specifically in the AddCdicData() function, where the bounds check improperly validates only part of the range accessed by the DecodeOne() function. As a result, a maliciously crafted .mobi file can exploit this vulnerability, reading an excessive number of bytes beyond the CDIC dictionary buffer. This exposure may lead to a crash of the application, potentially compromising its integrity and stability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
sumatrapdf <= 3.5.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
