VDB

CVE-2026-63729

CVE-2026-63729 PUBLISHED CVSS 6.8 MEDIUM

Reported by VulnCheck · Published July 21, 2026

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.

Risk Scores

CVSS 4.0
6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
TeX LiveTeX Live0, TeX Live 2026
TeX LiveTeX Live0, TeX Live 2026, 0
tugtex_live

Timeline

  • Jul 21, 2026 EPSS Score
  • Jul 21, 2026 CVE Published
  • Jul 23, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›