Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63729— TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File

CVSS 6.6 · Medium EPSS 0.12% · P2

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 2

VendorProductVersion RangeStatus
TeX LiveTeX Live≤ TeX Live 2025affected
TeX Live 2026unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-63729

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File
Source: CVE Program / CVE List V5
Vulnerability Description
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
释放后使用
Source: CVE Program / CVE List V5
Vulnerability Title
TeX Live 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TeX Live是Tex Live组织开源的一套专业的排版发行版。 TeX Live存在资源管理错误漏洞,该漏洞源于SyncTeX解析器中的堆释放后重用问题,导致在解析畸形.synctex或.synctex.gz文件时,可能造成应用程序崩溃或执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
TeX LiveTeX Live 0 ~ TeX Live 2025 -

II. Public POCs for CVE-2026-63729

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63729

登录查看更多情报信息。

Patches & Fixes for CVE-2026-63729 (1)

Vendor Advisories for CVE-2026-63729 (1)

Security Blog Posts for CVE-2026-63729 (1)

Vendor Pages for CVE-2026-63729 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-63729

No comments yet


Leave a comment