Описание
Security update for evince
This update for evince fixes the following issue:
- CVE-2026-63729: texlive: heap use-after-free in
synctex_parser.cvia a malformed.synctexor.synctex.gzfile (bsc#1272433).
Список пакетов
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
evince-45.0-150600.3.6.1
evince-devel-45.0-150600.3.6.1
evince-lang-45.0-150600.3.6.1
evince-plugin-djvudocument-45.0-150600.3.6.1
evince-plugin-dvidocument-45.0-150600.3.6.1
evince-plugin-pdfdocument-45.0-150600.3.6.1
evince-plugin-psdocument-45.0-150600.3.6.1
evince-plugin-tiffdocument-45.0-150600.3.6.1
evince-plugin-xpsdocument-45.0-150600.3.6.1
libevdocument3-4-45.0-150600.3.6.1
libevview3-3-45.0-150600.3.6.1
typelib-1_0-EvinceDocument-3_0-45.0-150600.3.6.1
typelib-1_0-EvinceView-3_0-45.0-150600.3.6.1
Ссылки
- Link for SUSE-SU-2026:3512-1
- E-Mail link for SUSE-SU-2026:3512-1
- SUSE Security Ratings
- SUSE Bug 1272433
- SUSE CVE CVE-2026-63729 page
Описание
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:evince-45.0-150600.3.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:evince-devel-45.0-150600.3.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:evince-lang-45.0-150600.3.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:evince-plugin-djvudocument-45.0-150600.3.6.1
Ссылки
- CVE-2026-63729
- SUSE Bug 1272431