CVE-2026-107738

Source
https://cve.org/CVERecord?id=CVE-2026-107738
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107738.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107738
Aliases
  • GHSA-33jg-vxm6-8mxx
Published
2026-10-08T22:35:30Z
Modified
2026-10-10T07:06:10Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
SumatraPDF: Untrusted binary record offset used without lower-bound validation
Details

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, ChmFile::GetCharZ() narrows file-controlled unsigned string offsets from /#WINDOWS and /#IVB to signed integers without a lower-bound check. An offset that becomes negative can make the function read before the /#STRINGS buffer, causing deterministic application termination. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107738.json"
}
References

Affected packages

Git / github.com/sumatrapdfreader/sumatrapdf

Affected ranges

Type
GIT
Repo
https://github.com/sumatrapdfreader/sumatrapdf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.6.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.4split
1.5split
1.6split
1.7split
1.8split
1.9split
2.*
2.0split
2.1split
2.2split
2.3split
2.4split
2.5split
3.*
3.0split
3.1.2rel
3.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107738.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "300426981365801951799513052451881105245",
                "44003461603035836753667947272880798217",
                "191448402986654612790008150530317847510",
                "180180430064954597980864822438408456421",
                "146721603798329529223172946927666931111",
                "165441435043455372111516623351820020634",
                "94396864851667047463377388242734878832",
                "251450456216546555062597820057147573120",
                "22661630783992783968356480019813172758",
                "211191342035911755034253341575008824875",
                "128943154191505563207805769665393005696",
                "1701251640089346248700938297385306289",
                "279802294764128008045833890763108672347",
                "241932673837966555736495986171706959117",
                "158462343271890274731363222281517084689"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107738-a40734dd",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/62254ed6d781ceb5cd16489bb423e7f591cd72c4",
        "target": {
            "file": "src/ChmFile.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "312024343921472359672318793875743238885",
            "length": 386
        },
        "id": "CVE-2026-107738-c1b66f3c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/62254ed6d781ceb5cd16489bb423e7f591cd72c4",
        "target": {
            "file": "src/ChmFile.cpp",
            "function": "GetCharZ"
        }
    }
]
vanir_signatures_modified
"2026-10-10T07:06:10Z"