Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107731— SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of service

Quick assessment

Affected
sumatrapdfreader sumatrapdf
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SumatraPDF 是一款面向 Windows 系统的多格式文档阅读器。在版本 3.7.0.22298 中,src/LitDoc.cpp 文件中存在四个独立可触发的范围校验变体漏洞。这些缺陷可能导致文件控制的偏移量和大小发生溢出、截断为负值,或在执行不完整的边界检查前发生回绕(wrap)。受影响的计算包括 contentOffset、目录表达式 dirOff64 + dirLen64、已解码段的偏移量与大小之和,以及次要头部(secondary-header)的范围处理逻辑。 通过打开经过精心构造的 LIT 文件

CVSS 5.5 · Medium

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107731

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of service
Source: CVE Program / CVE List V5
Vulnerability Description
SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, four independently reachable range-validation variants in src/LitDoc.cpp allow file-controlled offsets and sizes to overflow, narrow to negative values, or wrap before incomplete bounds checks. The affected calculations include contentOffset, the directory expression dirOff64 + dirLen64, and the decoded-section offset + size, along with secondary-header range handling. Opening a crafted LIT file that reaches one of these variants can cause invalid pointer reads and deterministic application termination. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
sumatrapdfreader sumatrapdf <= 3.7.0.22298 -

II. Public POCs for CVE-2026-107731

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107731

请登录查看更多情报信息。

Other References for CVE-2026-107731 (2)

Same Patch Batch · sumatrapdfreader · 2026-10-08 · 11 CVEs total

CVE-2026-107732 8.4 HIGH SumatraPDF: Markup/command-link injection into UI notification text
CVE-2026-107734 7.1 HIGH SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Executi
CVE-2026-107802 7.1 HIGH SumatraPDF — Windows command-line argument injection in AI selection-translate
CVE-2026-107733 6.8 MEDIUM SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open
CVE-2026-107736 6.8 MEDIUM SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata
CVE-2026-107738 6.8 MEDIUM SumatraPDF: Untrusted binary record offset used without lower-bound validation
CVE-2026-107737 5.7 MEDIUM SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup
CVE-2026-107729 5.5 MEDIUM SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes
CVE-2026-107730 5.5 MEDIUM SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read
CVE-2026-107735 5.4 MEDIUM SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initia

IV. Related Vulnerabilities

V. Comments for CVE-2026-107731

No comments yet


Leave a comment