{"id":"CVE-2026-55586","summary":"SumatraPDF: Heap out-of-bounds write in vendored CHMLib LZX Huffman table construction reachable from crafted CHM files","details":"SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply malformed LZX Huffman code lengths to make_decode_table in ext/CHMLib/lzx.c. In the long-code branch, the function writes new internal nodes through next_symbol before validating that the canonical Huffman table has overflowed. The PRETREE case can write beyond the 104-entry PRETREE_table into adjacent heap state in struct LZXstate when reached through chm_open, chm_retrieve_object, LZXdecompress, and BUILD_TABLE. This produces heap memory corruption in the parser process, while arbitrary code execution has not been demonstrated. No fixed version is available as of this review.","aliases":["GHSA-m423-rp8p-whj8"],"modified":"2026-08-24T03:59:15.782040Z","published":"2026-08-20T16:35:07.359Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-119","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55586.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55586.json"},{"type":"ADVISORY","url":"https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-m423-rp8p-whj8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55586"},{"type":"FIX","url":"https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sumatrapdfreader/sumatrapdf","events":[{"introduced":"0"},{"fixed":"13b3d4204dd12d93d426f2157b157b149edc29bf"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"3.6.1rel"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["3.2","3.1.2rel","3.0split","2.5split","2.4split","2.3split","2.2split","2.1split","2.0split","1.9split","1.8split","1.7split","1.6split","1.5split","1.4split"],"database_specific":{"vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf","target":{"function":"make_decode_table","file":"ext/CHMLib/lzx.c"},"deprecated":false,"digest":{"function_hash":"333466651800751386784968678698376194028","length":1150},"id":"CVE-2026-55586-33d90d36"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf","target":{"file":"src/Flags.cpp"},"deprecated":false,"digest":{"line_hashes":["177671882204301113280422802279050044422","26620336724865689684396516187992069053","123276839497677515914653543599139937329","324206445834261895260488051044139967948","274371785417562262774226980150761701388","134812799592600946655891857676065565440","113679281017239692281136640286098250475","78589323859569515700182538992184924089","110541703400306843843919183222958640916","159389642418757943216799085453158377160","22340947793455496966691221165217467435","206606855638962528231561804562460259533","3503848909521385358248225449473124758","51315661027982710574485391190973589568"],"threshold":0.9},"id":"CVE-2026-55586-3bf1f236"},{"deprecated":false,"digest":{"function_hash":"178801226923716997501815782287108463511","length":900},"id":"CVE-2026-55586-440c2380","signature_type":"Function","signature_version":"v1","source":"https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf","target":{"file":"src/Flags.cpp","function":"Flags::~Flags"}},{"id":"CVE-2026-55586-4d9b57bc","signature_type":"Line","signature_version":"v1","source":"https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf","target":{"file":"src/SumatraStartup.cpp"},"deprecated":false,"digest":{"line_hashes":["252785926045689090105925934796056552332","237593164361992583336357694505314014304","187983041947982357897651253758938977270","325358613223445933619435847005622860766","50440647055128840725273452426939413478","23288330587947363404755774236095692191","185876171766815245729381404858146648442","54289939130703932091443178319173249302","149379889568359869515649685830312614859"],"threshold":0.9}},{"signature_version":"v1","source":"https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf","target":{"file":"src/Flags.cpp","function":"ParseFlags"},"deprecated":false,"digest":{"function_hash":"260278129576066028231647026994909904072","length":9622},"id":"CVE-2026-55586-5dfdca3c","signature_type":"Function"},{"source":"https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf","target":{"file":"ext/CHMLib/lzx.h"},"deprecated":false,"digest":{"line_hashes":["5764663893405368688397072545521378215","111103137399420990503944349032444167507","271702138280848840092882818818405534006"],"threshold":0.9},"id":"CVE-2026-55586-76802e3d","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf","target":{"file":"src/SumatraStartup.cpp","function":"WinMain"},"deprecated":false,"digest":{"function_hash":"907585046289940280678462613265219312","length":11541},"id":"CVE-2026-55586-8f01f058"},{"deprecated":false,"digest":{"line_hashes":["81554873627085230445750292985880972092","222847510846130793673140604401394174680","186603889605839057154204174214355175907"],"threshold":0.9},"id":"CVE-2026-55586-a711dc4a","signature_type":"Line","signature_version":"v1","source":"https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf","target":{"file":"src/Flags.h"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf","target":{"file":"ext/CHMLib/lzx.c"},"deprecated":false,"digest":{"line_hashes":["224328496414094476845108136837497340834","203527598298679645738077421357593646931","307931480959380598160424050035174133318","97561556789632228295512545983578309457","178107192084937046608767651525726521786","59512798476285750558910172243102371303","284269273723614913305328573761363819577","4196990162895935633509295473411831909","168479539341170595307330117983100618835","190086275333835137763318709902024049787","16774836509040331144339608999852370261"],"threshold":0.9},"id":"CVE-2026-55586-d735e0fa"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55586.json","vanir_signatures_modified":"2026-08-24T03:59:15Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L"}]}