PatchSiren cyber security CVE debrief
CVE-2026-107729 sumatrapdfreader CVE debrief
A validation bypass in SumatraPDF's MOBI parsing can cause an out-of-bounds read, leading to a native access violation. This issue is triggered by a crafted MOBI file and results in a denial of service. No code execution, information disclosure, or integrity impact has been demonstrated. The vulnerability is caused by narrowing the untrusted unsigned mobiHdr.hdrLen field to a signed integer for validation, allowing values above INT_MAX to become negative and bypass the upper-bound check.
- Vendor
- sumatrapdfreader
- Product
- sumatrapdf
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for managing and securing SumatraPDF installations should assess exposure and prioritize verification and compensating controls. This includes reviewing inventory, applying compensating controls for affected versions, and monitoring for crafted MOBI files.
Why it matters
A validation bypass in SumatraPDF's MOBI parsing can cause an out-of-bounds read, leading to a denial of service. Defenders should prioritize verifying inventory and applying compensating controls for affected versions.
- Denial of service through native access violation
- Potential for data corruption or unexpected behavior
- Need for verification of inventory and compensating controls
- Possible impact on availability and system stability
Technical summary
In SumatraPDF 3.7.0.22298, the src/MobiDoc.cpp file narrows the untrusted unsigned mobiHdr.hdrLen field to a signed integer for validation, allowing values above INT_MAX to become negative and bypass the upper-bound check. When the EXTH flag is set, the original unsigned value is reused as a pointer offset, causing DecodeExthHeader() to read beyond the record buffer. This issue can cause a denial of service through a native access violation. No code execution, information disclosure, or integrity impact has been demonstrated.
Defensive priority
Defenders should prioritize verifying inventory and applying compensating controls for SumatraPDF versions 3.7.0.22298 and earlier.
Recommended defensive actions
- Verify inventory of SumatraPDF installations
- Apply compensating controls for affected versions
- Monitor for crafted MOBI files
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and source item provide details on the vulnerability, including its impact and affected versions. However, no fixed version is available as of this review. Defenders should verify inventory and apply compensating controls for affected SumatraPDF versions 3.7.0.22298 and earlier. The issue can be reliably terminated with a native access violation by opening a crafted MOBI file.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107729 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107729
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107729 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107729
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes out-of
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107729.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-86hq-m6hv-67h2
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/sumatrapdfreader/sumatrapdf/commit/1ef900cbad02f06353b0a0747b098ca596f7c131
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.