PT-2026-7171 · Sumatrapdf · Sumatrapdf

Haaeein

·

Published

2026-02-09

·

Updated

2026-02-10

·

CVE-2026-25920

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SumatraPDF versions 3.5.2 and earlier
Description A heap out-of-bounds read issue exists in SumatraPDF's MOBI HuffDic decompressor. The bounds check within the AddCdicData() function does not validate the complete range accessed by the DecodeOne() function. Processing a specially crafted MOBI file can result in reading approximately (1 << codeLength) bytes beyond the CDIC dictionary buffer, potentially causing a crash.
Recommendations Update SumatraPDF to a version later than 3.5.2.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-25920
GHSA-5MWX-65X7-CFFP

Affected Products

Sumatrapdf