CVE-2026-107738
Deferred Deferred - Pending Action

Out-of-Bounds Read in SumatraPDF via Negative String Offset

Vulnerability report for CVE-2026-107738, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, ChmFile::GetCharZ() narrows file-controlled unsigned string offsets from /#WINDOWS and /#IVB to signed integers without a lower-bound check. An offset that becomes negative can make the function read before the /#STRINGS buffer, causing deterministic application termination. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sumatrapdfreader sumatrapdf <= 3.6.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SumatraPDF versions 3.6.1 and earlier contain a vulnerability in the ChmFile::GetCharZ() function. This function processes unsigned string offsets from CHM files without checking for negative values. If an attacker crafts a CHM file with a negative offset, it can cause the function to read memory before the intended buffer, leading to a crash.

Detection Guidance

This vulnerability is specific to SumatraPDF versions 3.6.1 and earlier. Detection involves checking the installed version of SumatraPDF on your system. If you are running version 3.6.1 or earlier, your system is potentially vulnerable.

Impact Analysis

This vulnerability could allow an attacker to crash the SumatraPDF application by providing a specially crafted CHM file. The impact is limited to application termination under the conditions described in the advisory. No code execution or data theft is claimed.

Compliance Impact

The vulnerability causes deterministic application termination due to improper handling of file-controlled offsets, but no broader impact beyond the advisory is claimed. There is no evidence this vulnerability directly affects compliance with standards like GDPR or HIPAA.

Mitigation Strategies

Avoid using SumatraPDF versions 3.6.1 and earlier. Since no fixed version is available, consider switching to an alternative PDF reader until an update is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107738. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart