CVE-2026-107730: SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read
SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, LitParseHeader() in src/LitDoc.cpp computes the attacker-controlled hdrLen + nPieces 16 section offset using signed 32-bit arithmetic without validating the complete result. When the component values make that aggregate calculation overflow to a negative value, pointer construction reaches an invalid read in LitU32(), causing deterministic application termination. The supplied evidence does not demonstrate code execution, information disclosure, arbitrary read, or integrity impact. No fixed version is available as of this review.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to trigger the issue?
They must induce a user to open a crafted LIT document. Exploitation requires local access and user interaction, with no privileges required.
What is the demonstrated impact?
The documented outcome is deterministic termination of SumatraPDF caused by an invalid-pointer read. The supplied evidence does not demonstrate code execution, information disclosure, arbitrary reads, or integrity impact.
Which installations are known to be affected?
The issue is described in SumatraPDF version 3.7.0.22298. The provided data does not establish the full affected version range or whether default configurations are affected.
Is a fix available?
No fixed version was available as of the review. Until an update is available, avoid opening untrusted LIT files in SumatraPDF.