PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107731 sumatrapdfreader CVE debrief

SumatraPDF 3.7.0.22298 LIT parser range-validation flaws cause invalid-pointer reads and denial of service through four independently reachable variants in src/LitDoc.cpp, allowing file-controlled offsets and sizes to overflow, narrow to negative values, or wrap before incomplete bounds checks, impacting defenders and administrators who should assess exposure and prioritize verification of these flaws to prevent crafted LIT file attacks and ensure application integrity. This vulnerability affects SumatraPDF users and defenders who need to verify the presence of range-validation flaws in the LIT parser, assess potential denial of service and invalid-pointer read impacts, and take

Vendor
sumatrapdfreader
Product
sumatrapdf
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-09
Advisory published
2026-10-08
Advisory updated
2026-10-09

Who should care

Defenders and administrators of SumatraPDF 3.7.0.22298 should assess exposure to crafted LIT files, prioritize verification of range-validation flaws in src/LitDoc.cpp, and monitor for potential denial of service and invalid-pointer read impacts. They should also verify the presence of these flaws, review compensating controls, and track exceptions to ensure application integrity and security. This includes reviewing relevant monitoring, detection, and

Why it matters

CVE-2026-107731 allows denial of service and invalid-pointer reads in SumatraPDF 3.7.0.22298 through range-validation flaws; defenders should assess exposure, prioritize verification, and monitor for crafted LIT files.

  • Denial of service through crafted LIT files
  • Invalid-pointer reads requiring verification
  • Range-validation flaws requiring patching
  • Exposure assessment and monitoring priority

Technical summary

Four independently reachable range-validation variants in src/LitDoc.cpp allow file-controlled offsets and sizes to overflow, narrow to negative values, or wrap before incomplete bounds checks. These variants impact contentOffset, directory expression dirOff64 + dirLen64, decoded-section offset + size, and secondary-header range handling, causing invalid pointer reads and deterministic application termination when a crafted LIT file is opened. Defenders should focus on verifying these flaws, assessing exposure, and monitoring for potential attacks. The affected calculations include contentOffset, which can lead to denial of service and invalid-pointer reads in SumatraPDF 3.7.0.22298.

Defensive priority

Assess exposure, prioritize verification, and monitor for crafted LIT files

Recommended defensive actions

  • Assess exposure to crafted LIT files in SumatraPDF 3.7.0.22298
  • Prioritize verification of range-validation flaws in src/LitDoc.cpp
  • Monitor for and restrict crafted LIT files
  • Verify vendor remediation status
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

Official CVE Program record and NVD vulnerability detail provide information on range-validation variants in src/LitDoc.cpp, allowing file-controlled offsets and sizes to overflow, narrow to negative values, or wrap before incomplete bounds checks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107731 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107731

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107731 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107731

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.