PT-2026-46057 · Libxls · Libxls

Richard Howe

+1

·

Published

2026-06-03

·

Updated

2026-06-04

·

CVE-2026-26824

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions libxls versions prior to 1.6.4
Description The OLE container parser contains an issue where memory allocated for the Master Sector Allocation Table (MSAT) in the read MSAT() function is not fully initialized before being used by the ole2 validate sector chain() function. This can lead to application crashes or potential information disclosure when the software processes a specially crafted XLS file.
Recommendations Update to a version newer than 1.6.3.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-26824

Affected Products

Libxls