PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107729 sumatrapdfreader CVE debrief

A validation bypass in SumatraPDF's MOBI parsing can cause an out-of-bounds read, leading to a native access violation. This issue is triggered by a crafted MOBI file and results in a denial of service. No code execution, information disclosure, or integrity impact has been demonstrated. The vulnerability is caused by narrowing the untrusted unsigned mobiHdr.hdrLen field to a signed integer for validation, allowing values above INT_MAX to become negative and bypass the upper-bound check.

Vendor
sumatrapdfreader
Product
sumatrapdf
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-09
Advisory published
2026-10-08
Advisory updated
2026-10-09

Who should care

Defenders responsible for managing and securing SumatraPDF installations should assess exposure and prioritize verification and compensating controls. This includes reviewing inventory, applying compensating controls for affected versions, and monitoring for crafted MOBI files.

Why it matters

A validation bypass in SumatraPDF's MOBI parsing can cause an out-of-bounds read, leading to a denial of service. Defenders should prioritize verifying inventory and applying compensating controls for affected versions.

  • Denial of service through native access violation
  • Potential for data corruption or unexpected behavior
  • Need for verification of inventory and compensating controls
  • Possible impact on availability and system stability

Technical summary

In SumatraPDF 3.7.0.22298, the src/MobiDoc.cpp file narrows the untrusted unsigned mobiHdr.hdrLen field to a signed integer for validation, allowing values above INT_MAX to become negative and bypass the upper-bound check. When the EXTH flag is set, the original unsigned value is reused as a pointer offset, causing DecodeExthHeader() to read beyond the record buffer. This issue can cause a denial of service through a native access violation. No code execution, information disclosure, or integrity impact has been demonstrated.

Defensive priority

Defenders should prioritize verifying inventory and applying compensating controls for SumatraPDF versions 3.7.0.22298 and earlier.

Recommended defensive actions

  • Verify inventory of SumatraPDF installations
  • Apply compensating controls for affected versions
  • Monitor for crafted MOBI files
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and source item provide details on the vulnerability, including its impact and affected versions. However, no fixed version is available as of this review. Defenders should verify inventory and apply compensating controls for affected SumatraPDF versions 3.7.0.22298 and earlier. The issue can be reliably terminated with a native access violation by opening a crafted MOBI file.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107729 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107729

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107729 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107729

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.