Heap Use-After-Free Vulnerability in TeX Live's SyncTeX Parser Affects GNOME Evince
CVE-2026-63729

6.8MEDIUM

Key Information:

Vendor

Tex Live

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-63729?

The SyncTeX parser included with TeX Live and utilized by applications like GNOME Evince is susceptible to a heap use-after-free vulnerability. This issue arises when an attacker provides a malformed .synctex or .synctex.gz file, which leads to the construction of a reference node with a NULL parent pointer. Consequently, this situation disrupts the detachment process of the node from its sibling chain, leading to recursive freeing of active tree nodes. The resultant dangling pointers can be accessed by the parser, resulting in potential application crashes or arbitrary code execution during the document loading process, posing significant security risks.

Affected Version(s)

TeX Live 0

TeX Live 0

TeX Live TeX Live 2026

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fatih Çelik
.