{"id":"DEBIAN-CVE-2026-63729","details":"The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.","modified":"2026-09-01T16:06:55.159630768Z","published":"2026-07-21T03:16:42.470Z","upstream":["CVE-2026-63729"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-63729"}],"affected":[{"package":{"name":"okular","ecosystem":"Debian:12","purl":"pkg:deb/debian/okular?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4:22.12.3-1","4:22.12.3-1+deb12u1","4:23.08.1-1","4:23.08.1-2","4:24.05.2-1","4:24.05.2-2","4:24.05.2-3","4:24.05.2-4","4:24.08.2-1","4:24.08.2-2","4:24.12.0-1","4:24.12.0-2","4:24.12.2-1","4:25.03.90-1","4:25.04.0-1","4:25.04.2-1","4:25.04.2-2","4:25.08.3-1","4:25.11.90-1","4:26.04.0-1","4:26.04.2-1","4:26.08.0-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"}},{"package":{"name":"okular","ecosystem":"Debian:13","purl":"pkg:deb/debian/okular?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4:25.04.2-1","4:25.04.2-1+deb13u1","4:25.04.2-2","4:25.08.3-1","4:25.11.90-1","4:26.04.0-1","4:26.04.2-1","4:26.08.0-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"}},{"package":{"name":"okular","ecosystem":"Debian:14","purl":"pkg:deb/debian/okular?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4:25.04.2-1","4:25.04.2-2","4:25.08.3-1","4:25.11.90-1","4:26.04.0-1","4:26.04.2-1","4:26.08.0-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"}},{"package":{"name":"texlive-bin","ecosystem":"Debian:12","purl":"pkg:deb/debian/texlive-bin?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2022.20220321.62855-5.1","2022.20220321.62855-5.1+deb12u1","2022.20220321.62855-5.1+deb12u2","2022.20220321.62855-6","2022.20220321.62855-7","2022.20220321.62855-8","2023.20230311.66589-1","2023.20230311.66589-2","2023.20230311.66589-3","2023.20230311.66589-4","2023.20230311.66589-5","2023.20230311.66589-6","2023.20230311.66589-7","2023.20230311.66589-8","2023.20230311.66589-9","2024.20240313.70630+ds-1","2024.20240313.70630+ds-2","2024.20240313.70630+ds-3","2024.20240313.70630+ds-4","2024.20240313.70630+ds-5","2024.20240313.70630+ds-6","2025.20250727.75242+ds-1","2025.20250727.75242+ds-2","2025.20250727.75242+ds-3","2025.20250727.75242+ds-4","2025.20250727.75242+ds-5","2025.20250727.75242+ds-5~hurd.1","2026.20260303.78225+ds-1","2026.20260303.78225+ds-2","2026.20260303.78225+ds-3","2026.20260303.78225+ds-4","2026.20260303.78225+ds-5"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"}},{"package":{"name":"texlive-bin","ecosystem":"Debian:13","purl":"pkg:deb/debian/texlive-bin?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2024.20240313.70630+ds-6","2025.20250727.75242+ds-1","2025.20250727.75242+ds-2","2025.20250727.75242+ds-3","2025.20250727.75242+ds-4","2025.20250727.75242+ds-5","2025.20250727.75242+ds-5~hurd.1","2026.20260303.78225+ds-1","2026.20260303.78225+ds-2","2026.20260303.78225+ds-3","2026.20260303.78225+ds-4","2026.20260303.78225+ds-5"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"}},{"package":{"name":"texlive-bin","ecosystem":"Debian:14","purl":"pkg:deb/debian/texlive-bin?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.20260303.78225+ds-2"}]}],"versions":["2024.20240313.70630+ds-6","2025.20250727.75242+ds-1","2025.20250727.75242+ds-2","2025.20250727.75242+ds-3","2025.20250727.75242+ds-4","2025.20250727.75242+ds-5","2025.20250727.75242+ds-5~hurd.1","2026.20260303.78225+ds-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"}},{"package":{"name":"texstudio","ecosystem":"Debian:12","purl":"pkg:deb/debian/texstudio?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3.1+ds-2","4.3.1+ds-3","4.7.2+ds-1","4.7.2+ds-2","4.8.0+ds-1","4.8.1+ds-1","4.8.2+ds-1","4.8.4+ds-1","4.8.4+ds-2","4.8.5+ds-1","4.8.6+ds-1","4.8.7+ds-1","4.8.8+ds-1","4.8.9+ds-1","4.9.0+ds-1","4.9.1+ds-1","4.9.2+ds-1","4.9.6+ds-1","4.9.7+ds-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"}},{"package":{"name":"texstudio","ecosystem":"Debian:13","purl":"pkg:deb/debian/texstudio?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.8.7+ds-1","4.8.8+ds-1","4.8.9+ds-1","4.9.0+ds-1","4.9.1+ds-1","4.9.2+ds-1","4.9.6+ds-1","4.9.7+ds-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"}},{"package":{"name":"texstudio","ecosystem":"Debian:14","purl":"pkg:deb/debian/texstudio?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.9.6+ds-1"}]}],"versions":["4.8.7+ds-1","4.8.8+ds-1","4.8.9+ds-1","4.9.0+ds-1","4.9.1+ds-1","4.9.2+ds-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63729.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}