CVE-2026-23951: SumatraPDF's Integer Underflow in PalmDbReader Leads to Crash
SumatraPDF is a multi-format reader for Windows. All versions contain an off-by-one error in the validation code that only triggers with exactly 2 records, causing an integer underflow in the size calculation. This bug exists in PalmDbReader::GetRecord when opening a crafted Mobi file, resulting in an out-of-bounds heap read that crashes the app. There are no published fixes at the time of publication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23951?
CVE-2026-23951 is classified as a critical vulnerability due to its potential to cause crashes and affect the usability of SumatraPDF.
How does CVE-2026-23951 affect SumatraPDF?
CVE-2026-23951 affects all versions of SumatraPDF by allowing an integer underflow during the reading of PalmDb files with exactly two records.
How do I fix CVE-2026-23951?
To fix CVE-2026-23951, update to the latest version of SumatraPDF that addresses this vulnerability.
What are the potential impacts of CVE-2026-23951?
The primary impact of CVE-2026-23951 is that it may lead to application crashes, resulting in a denial of service for users.
Is CVE-2026-23951 a widespread vulnerability?
CVE-2026-23951 could be considered widespread as it affects all versions of SumatraPDF, a commonly used multi-format reader.