DEBIAN-CVE-2026-63729

Source
https://security-tracker.debian.org/tracker/CVE-2026-63729
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-63729
Upstream
Published
2026-07-21T03:16:42Z
Modified
2026-09-01T16:06:55Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.

References

Affected packages

Debian:12
okular

Package

Name
okular
Purl
pkg:deb/debian/okular?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4:22.*
4:22.12.3-1
4:22.12.3-1+deb12u1
4:23.*
4:23.08.1-1
4:23.08.1-2
4:24.*
4:24.05.2-1
4:24.05.2-2
4:24.05.2-3
4:24.05.2-4
4:24.08.2-1
4:24.08.2-2
4:24.12.0-1
4:24.12.0-2
4:24.12.2-1
4:25.*
4:25.03.90-1
4:25.04.0-1
4:25.04.2-1
4:25.04.2-2
4:25.08.3-1
4:25.11.90-1
4:26.*
4:26.04.0-1
4:26.04.2-1
4:26.08.0-1

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"
texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2022.*
2022.20220321.62855-5.1
2022.20220321.62855-5.1+deb12u1
2022.20220321.62855-5.1+deb12u2
2022.20220321.62855-6
2022.20220321.62855-7
2022.20220321.62855-8
2023.*
2023.20230311.66589-1
2023.20230311.66589-2
2023.20230311.66589-3
2023.20230311.66589-4
2023.20230311.66589-5
2023.20230311.66589-6
2023.20230311.66589-7
2023.20230311.66589-8
2023.20230311.66589-9
2024.*
2024.20240313.70630+ds-1
2024.20240313.70630+ds-2
2024.20240313.70630+ds-3
2024.20240313.70630+ds-4
2024.20240313.70630+ds-5
2024.20240313.70630+ds-6
2025.*
2025.20250727.75242+ds-1
2025.20250727.75242+ds-2
2025.20250727.75242+ds-3
2025.20250727.75242+ds-4
2025.20250727.75242+ds-5~hurd.1
2025.20250727.75242+ds-5
2026.*
2026.20260303.78225+ds-1
2026.20260303.78225+ds-2
2026.20260303.78225+ds-3
2026.20260303.78225+ds-4
2026.20260303.78225+ds-5

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"
texstudio

Package

Name
texstudio
Purl
pkg:deb/debian/texstudio?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.3.1+ds-2
4.3.1+ds-3
4.7.2+ds-1
4.7.2+ds-2
4.8.0+ds-1
4.8.1+ds-1
4.8.2+ds-1
4.8.4+ds-1
4.8.4+ds-2
4.8.5+ds-1
4.8.6+ds-1
4.8.7+ds-1
4.8.8+ds-1
4.8.9+ds-1
4.9.0+ds-1
4.9.1+ds-1
4.9.2+ds-1
4.9.6+ds-1
4.9.7+ds-1

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"
Debian:13
okular

Package

Name
okular
Purl
pkg:deb/debian/okular?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4:25.*
4:25.04.2-1
4:25.04.2-1+deb13u1
4:25.04.2-2
4:25.08.3-1
4:25.11.90-1
4:26.*
4:26.04.0-1
4:26.04.2-1
4:26.08.0-1

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"
texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2024.*
2024.20240313.70630+ds-6
2025.*
2025.20250727.75242+ds-1
2025.20250727.75242+ds-2
2025.20250727.75242+ds-3
2025.20250727.75242+ds-4
2025.20250727.75242+ds-5~hurd.1
2025.20250727.75242+ds-5
2026.*
2026.20260303.78225+ds-1
2026.20260303.78225+ds-2
2026.20260303.78225+ds-3
2026.20260303.78225+ds-4
2026.20260303.78225+ds-5

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"
texstudio

Package

Name
texstudio
Purl
pkg:deb/debian/texstudio?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.8.7+ds-1
4.8.8+ds-1
4.8.9+ds-1
4.9.0+ds-1
4.9.1+ds-1
4.9.2+ds-1
4.9.6+ds-1
4.9.7+ds-1

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"
Debian:14
okular

Package

Name
okular
Purl
pkg:deb/debian/okular?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4:25.*
4:25.04.2-1
4:25.04.2-2
4:25.08.3-1
4:25.11.90-1
4:26.*
4:26.04.0-1
4:26.04.2-1
4:26.08.0-1

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"
texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.20260303.78225+ds-2

Affected versions

2024.*
2024.20240313.70630+ds-6
2025.*
2025.20250727.75242+ds-1
2025.20250727.75242+ds-2
2025.20250727.75242+ds-3
2025.20250727.75242+ds-4
2025.20250727.75242+ds-5~hurd.1
2025.20250727.75242+ds-5
2026.*
2026.20260303.78225+ds-1

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"
texstudio

Package

Name
texstudio
Purl
pkg:deb/debian/texstudio?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.9.6+ds-1

Affected versions

4.*
4.8.7+ds-1
4.8.8+ds-1
4.8.9+ds-1
4.9.0+ds-1
4.9.1+ds-1
4.9.2+ds-1

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"