CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chmlib.c chmdecompressblock integer overflow. There is a resultant heap-based buffer overflow in chmfetch_bytes.
"2026-04-12T15:59:36Z"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2bef8d0"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48172.json"
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"195892175625739598384565738886928693113",
"149253868867704403655622444990774444724",
"103492216121940087843497286654604125259",
"297680089826767714702311139057703178215",
"80842639067664548787265453842758717036",
"314010403109654087180972229494859459488"
]
},
"target": {
"file": "ext/CHMLib/chm_lib.c"
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-48172-611254ad",
"source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/08179946a745cf1605e4b9670942ec1a6e1f4c5d"
},
{
"digest": {
"length": 739.0,
"function_hash": "286458521566129013419023656621431881358"
},
"target": {
"file": "ext/CHMLib/chm_lib.c",
"function": "_unmarshal_lzxc_reset_table"
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-48172-c028f054",
"source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/08179946a745cf1605e4b9670942ec1a6e1f4c5d"
}
]