PT-2026-3887 · Unknown · Sumatrapdf

Ub1Cu0

·

Published

2026-01-22

·

Updated

2026-02-17

·

CVE-2026-23951

CVSS v3.1
5.5
VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SumatraPDF (affected versions not specified)
Description SumatraPDF, a multi-format reader for Windows, contains an off-by-one error in the validation code that triggers only with exactly two records. This error causes an integer underflow in the size calculation within the
PalmDbReader::GetRecord
function when opening a crafted Mobi file. This results in an out-of-bounds heap read, leading to application crashes. The issue may potentially lead to remote code execution via malicious PDF files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Out of bounds Read

Integer Underflow

Weakness Enumeration

Related Identifiers

CVE-2026-23951
GHSA-HJ4W-C5X8-P2HV

Affected Products

Sumatrapdf