CVE-2026-107736
SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, MaybeFlipBitmap() asks GDI+ to read the attacker-controlled PropertyTagOrientation size through GetPropertyItem() while supplying only a fixed 64-byte buf on the stack. Opening a crafted TIFF with enough EXIF Orientation values can cause attacker-selected bytes to overwrite stack control data, while tested builds terminate through the stack cookie check. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
| CWE | CWE-121 |
| Vendor | sumatrapdfreader |
| Product | sumatrapdf |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for sumatrapdfreader sumatrapdf
Be the first to know when new unknown vulnerabilities affecting sumatrapdfreader sumatrapdf are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
sumatrapdfreader / sumatrapdf
<= 3.6.1