CVE-2026-107730: SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read

Published Oct 8, 2026
·
Updated

SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, LitParseHeader() in src/LitDoc.cpp computes the attacker-controlled hdrLen + nPieces 16 section offset using signed 32-bit arithmetic without validating the complete result. When the component values make that aggregate calculation overflow to a negative value, pointer construction reaches an invalid read in LitU32(), causing deterministic application termination. The supplied evidence does not demonstrate code execution, information disclosure, arbitrary read, or integrity impact. No fixed version is available as of this review.

Affected Software

1 affected component
SumatraPDF SumatraPDF=3.7.0.22298

Event History

Oct 8, 2026
CVE Published
via MITRE·10:19 PM
Data Sourced
via MITRE·10:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What must an attacker do to trigger the issue?

They must induce a user to open a crafted LIT document. Exploitation requires local access and user interaction, with no privileges required.

2

What is the demonstrated impact?

The documented outcome is deterministic termination of SumatraPDF caused by an invalid-pointer read. The supplied evidence does not demonstrate code execution, information disclosure, arbitrary reads, or integrity impact.

3

Which installations are known to be affected?

The issue is described in SumatraPDF version 3.7.0.22298. The provided data does not establish the full affected version range or whether default configurations are affected.

4

Is a fix available?

No fixed version was available as of the review. Until an update is available, avoid opening untrusted LIT files in SumatraPDF.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203