CVE-2025-48172: Chmlib
Medium severity, CVSS 5.6. EPSS: 0.2% chance of exploitation in the next 30 days.
CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes.
Affected products
- Chmlib Chmlib
Published 2025-07-04. Last modified 2026-06-17.