libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not fully initialized before being consumed by ole2_validate_sector_chain(), which may result in application crashes or potential information disclosure when processing a crafted XLS file
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26824.json"
}{
"cpe": "cpe:2.3:a:libxls_project:libxls:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.3"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26824.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "203694048921706848705291308481034899029",
"length": 175
},
"id": "CVE-2026-26824-2b1f86d8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libxls/libxls/commit/9adebc9b6d60db21f25ddc898e8760eeb69d6529",
"target": {
"file": "src/ole.c",
"function": "ole_realloc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "269969135579211647760887673572161541183",
"length": 3632
},
"id": "CVE-2026-26824-ac133ef5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libxls/libxls/commit/9adebc9b6d60db21f25ddc898e8760eeb69d6529",
"target": {
"file": "src/ole.c",
"function": "ole2_read_body"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"31201090368234119660327293564796487718",
"5464812486148276938682733703097698230",
"181459569261252980396171505662258551276",
"202343728789656790139685654959685939682",
"166687887979456724030056461974959734303",
"104408711004474999019669019722207902085",
"38628912741914539762157171289821661599",
"92360512358621844534806472519316749115",
"258868731064355069317933935683611111411",
"124733351830048353461415058262882332888",
"44802654194229965728910378356916406650",
"311152670102729036540203116047052451318",
"302312943263996706690526013584864299129",
"298007449445934188226640098149559318798",
"89848575369632357630024886563347156216",
"171067523382525194673342992912619328174",
"35171795934412749961536147925581739087",
"203434135079934351500559014613689934547",
"24397105516967715880484607430856343084",
"103292368750331459169211366477507029217",
"274018136924391154233096253883616687660",
"279569109750500222605074773558779863520",
"53743936028039960269390625333808440569",
"208718177435390463928858383558195800357",
"6644689110670771846816674643129135482",
"141042685295067955305007363603678293492",
"253924172715329005734323800723508116024",
"21265116374512711224656740501895329550",
"89479945496526359049349283521199415049"
],
"threshold": 0.9
},
"id": "CVE-2026-26824-b2a29394",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libxls/libxls/commit/9adebc9b6d60db21f25ddc898e8760eeb69d6529",
"target": {
"file": "src/ole.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "155987069844193893342406306415169294331",
"length": 250
},
"id": "CVE-2026-26824-cd2e47e7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libxls/libxls/commit/9adebc9b6d60db21f25ddc898e8760eeb69d6529",
"target": {
"file": "src/ole.c",
"function": "ole2_validate_sector_chain"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "294071583593163361935094640769182333662",
"length": 539
},
"id": "CVE-2026-26824-dc7ebea4",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libxls/libxls/commit/9adebc9b6d60db21f25ddc898e8760eeb69d6529",
"target": {
"file": "src/ole.c",
"function": "read_MSAT_header"
}
}
]
"2026-09-25T08:11:23Z"