CVE-2026-107729
Description détaillée
SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, src/MobiDoc.cpp narrows the untrusted unsigned mobiHdr.hdrLen field to a signed integer for validation; values above INT_MAX become negative and bypass the upper-bound check. When the EXTH flag is set, the original unsigned value is reused as a pointer offset, causing DecodeExthHeader() to read beyond the record buffer. Opening a crafted MOBI file can reliably terminate the application with a native access violation; no code execution, information disclosure, or integrity impact has been demonstrated. No fixed version is available as of this review.
Vecteur d'attaque (CVSS)
Dernières Vulnérabilités
CVE-2026-97032
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
CVE-2026-97031
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
CVE-2026-97030
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
