CVE-2026-107736: SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, MaybeFlipBitmap() asks GDI+ to read the attacker-controlled PropertyTagOrientation size through GetPropertyItem() while supplying only a fixed 64-byte buf on the stack. Opening a crafted TIFF with enough EXIF Orientation values can cause attacker-selected bytes to overwrite stack control data, while tested builds terminate through the stack cookie check. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Windows users of SumatraPDF 3.6.1 and earlier are exposed when the application opens a crafted TIFF file containing oversized EXIF Orientation metadata.
What does exploitation require?
An attacker needs to induce the target to open a malicious TIFF. The crafted Orientation metadata can cause attacker-selected bytes to overwrite stack control data.
What happens in the tested builds?
Tested builds terminate through the stack cookie check after the overflow. The advisory does not claim broader impact beyond these supported conditions.
Is a fixed version available?
No fixed version was available as of the review.