Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-63729

Опубликовано: 21 июл. 2026
Источник: redhat
CVSS3: 6.6

Описание

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.

A flaw was found in the SyncTeX parser, part of TeX Live and used by applications like GNOME Evince. A remote attacker could exploit a heap use-after-free vulnerability by providing a specially crafted SyncTeX file (e.g., .synctex or .synctex.gz). This could lead to application crashes or, in severe cases, allow the attacker to execute arbitrary code on the affected system.

Отчет

The SyncTeX parser shipped with TeX Live and embedded by GNOME Evince in Red Hat Enterprise Linux is affected by this vulnerability. A heap use-after-free in synctex_parser.c can be triggered by opening a specially crafted .synctex file, potentially leading to application crashes or code execution. All shipped versions of TeX Live (pre-2026) and evince are within the affected range.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10texliveFix deferred
Red Hat Enterprise Linux 6evinceFix deferred
Red Hat Enterprise Linux 6texliveFix deferred
Red Hat Enterprise Linux 7evinceFix deferred
Red Hat Enterprise Linux 7texliveFix deferred
Red Hat Enterprise Linux 8evinceFix deferred
Red Hat Enterprise Linux 8texliveFix deferred
Red Hat Enterprise Linux 9evinceFix deferred
Red Hat Enterprise Linux 9texliveFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2503120texlive: evince: TeX Live SyncTeX Parser: Heap use-after-free allows arbitrary code execution via malformed file

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
13 дней назад

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.

CVSS3: 6.6
nvd
13 дней назад

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.

CVSS3: 6.6
debian
13 дней назад

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedd ...

CVSS3: 6.6
github
13 дней назад

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.

6.6 Medium

CVSS3