CVE-2026-26824

Source
https://cve.org/CVERecord?id=CVE-2026-26824
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26824.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-26824
Downstream
Published
2026-06-03T00:00:00Z
Modified
2026-09-25T08:11:23Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVSS Calculator
Summary
[none]
Details

libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not fully initialized before being consumed by ole2_validate_sector_chain(), which may result in application crashes or potential information disclosure when processing a crafted XLS file

Database specific
{
    "cna_assigner":  "mitre",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26824.json"
}
References

Affected packages

Git / github.com/libxls/libxls

Affected ranges

Type
GIT
Repo
https://github.com/libxls/libxls
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:libxls_project:libxls:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "1.6.3"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.2.0
v0.3.0
v1.*
v1.0.0
v1.1.0
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.4.0
v1.5.0
v1.5.0-rc0
v1.5.0-rc1
v1.5.0-rc2
v1.5.0-rc3
v1.5.0-rc4
v1.5.1
v1.5.1-rc0
v1.5.1-rc1
v1.5.2
v1.5.2-rc0
v1.5.3
v1.5.3-rc0
v1.6.0
v1.6.0-rc0
v1.6.1
v1.6.2
v1.6.2-rc0
v1.6.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26824.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "203694048921706848705291308481034899029",
            "length":  175
        },
        "id":  "CVE-2026-26824-2b1f86d8",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/libxls/libxls/commit/9adebc9b6d60db21f25ddc898e8760eeb69d6529",
        "target":  {
            "file":  "src/ole.c",
            "function":  "ole_realloc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "269969135579211647760887673572161541183",
            "length":  3632
        },
        "id":  "CVE-2026-26824-ac133ef5",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/libxls/libxls/commit/9adebc9b6d60db21f25ddc898e8760eeb69d6529",
        "target":  {
            "file":  "src/ole.c",
            "function":  "ole2_read_body"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "31201090368234119660327293564796487718",
                "5464812486148276938682733703097698230",
                "181459569261252980396171505662258551276",
                "202343728789656790139685654959685939682",
                "166687887979456724030056461974959734303",
                "104408711004474999019669019722207902085",
                "38628912741914539762157171289821661599",
                "92360512358621844534806472519316749115",
                "258868731064355069317933935683611111411",
                "124733351830048353461415058262882332888",
                "44802654194229965728910378356916406650",
                "311152670102729036540203116047052451318",
                "302312943263996706690526013584864299129",
                "298007449445934188226640098149559318798",
                "89848575369632357630024886563347156216",
                "171067523382525194673342992912619328174",
                "35171795934412749961536147925581739087",
                "203434135079934351500559014613689934547",
                "24397105516967715880484607430856343084",
                "103292368750331459169211366477507029217",
                "274018136924391154233096253883616687660",
                "279569109750500222605074773558779863520",
                "53743936028039960269390625333808440569",
                "208718177435390463928858383558195800357",
                "6644689110670771846816674643129135482",
                "141042685295067955305007363603678293492",
                "253924172715329005734323800723508116024",
                "21265116374512711224656740501895329550",
                "89479945496526359049349283521199415049"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-26824-b2a29394",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/libxls/libxls/commit/9adebc9b6d60db21f25ddc898e8760eeb69d6529",
        "target":  {
            "file":  "src/ole.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "155987069844193893342406306415169294331",
            "length":  250
        },
        "id":  "CVE-2026-26824-cd2e47e7",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/libxls/libxls/commit/9adebc9b6d60db21f25ddc898e8760eeb69d6529",
        "target":  {
            "file":  "src/ole.c",
            "function":  "ole2_validate_sector_chain"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "294071583593163361935094640769182333662",
            "length":  539
        },
        "id":  "CVE-2026-26824-dc7ebea4",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/libxls/libxls/commit/9adebc9b6d60db21f25ddc898e8760eeb69d6529",
        "target":  {
            "file":  "src/ole.c",
            "function":  "read_MSAT_header"
        }
    }
]
vanir_signatures_modified
"2026-09-25T08:11:23Z"