PatchSiren cyber security CVE debrief
CVE-2026-107731 sumatrapdfreader CVE debrief
SumatraPDF 3.7.0.22298 LIT parser range-validation flaws cause invalid-pointer reads and denial of service through four independently reachable variants in src/LitDoc.cpp, allowing file-controlled offsets and sizes to overflow, narrow to negative values, or wrap before incomplete bounds checks, impacting defenders and administrators who should assess exposure and prioritize verification of these flaws to prevent crafted LIT file attacks and ensure application integrity. This vulnerability affects SumatraPDF users and defenders who need to verify the presence of range-validation flaws in the LIT parser, assess potential denial of service and invalid-pointer read impacts, and take
- Vendor
- sumatrapdfreader
- Product
- sumatrapdf
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-09
Who should care
Defenders and administrators of SumatraPDF 3.7.0.22298 should assess exposure to crafted LIT files, prioritize verification of range-validation flaws in src/LitDoc.cpp, and monitor for potential denial of service and invalid-pointer read impacts. They should also verify the presence of these flaws, review compensating controls, and track exceptions to ensure application integrity and security. This includes reviewing relevant monitoring, detection, and
Why it matters
CVE-2026-107731 allows denial of service and invalid-pointer reads in SumatraPDF 3.7.0.22298 through range-validation flaws; defenders should assess exposure, prioritize verification, and monitor for crafted LIT files.
- Denial of service through crafted LIT files
- Invalid-pointer reads requiring verification
- Range-validation flaws requiring patching
- Exposure assessment and monitoring priority
Technical summary
Four independently reachable range-validation variants in src/LitDoc.cpp allow file-controlled offsets and sizes to overflow, narrow to negative values, or wrap before incomplete bounds checks. These variants impact contentOffset, directory expression dirOff64 + dirLen64, decoded-section offset + size, and secondary-header range handling, causing invalid pointer reads and deterministic application termination when a crafted LIT file is opened. Defenders should focus on verifying these flaws, assessing exposure, and monitoring for potential attacks. The affected calculations include contentOffset, which can lead to denial of service and invalid-pointer reads in SumatraPDF 3.7.0.22298.
Defensive priority
Assess exposure, prioritize verification, and monitor for crafted LIT files
Recommended defensive actions
- Assess exposure to crafted LIT files in SumatraPDF 3.7.0.22298
- Prioritize verification of range-validation flaws in src/LitDoc.cpp
- Monitor for and restrict crafted LIT files
- Verify vendor remediation status
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Official CVE Program record and NVD vulnerability detail provide information on range-validation variants in src/LitDoc.cpp, allowing file-controlled offsets and sizes to overflow, narrow to negative values, or wrap before incomplete bounds checks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107731 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107731
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107731 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107731
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of service
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107731.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-753j-hx3p-xm9g
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/sumatrapdfreader/sumatrapdf/commit/5d43b8cf9c45335ffd47e616bfa27648f17d0b63
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.