CVE-2026-39855

Source
https://cve.org/CVERecord?id=CVE-2026-39855
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39855.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-39855
Aliases
  • GHSA-76vv-x5rr-q3mr
Downstream
Published
2026-04-09T15:58:38Z
Modified
2026-08-12T16:23:58Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
osslsigncode has an Integer Underflow in PE Page Hash Calculation Can Cause Out-of-Bounds Read
Details

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation code (pe_page_hash_calc()). When page hash processing is performed on a PE file, the function subtracts hdrsize from pagesize without first validating that pagesize >= hdrsize. If a malicious PE file sets SizeOfHeaders (hdrsize) larger than SectionAlignment (pagesize), the subtraction underflows and produces a very large unsigned length. The code allocates a zero-filled buffer of pagesize bytes and then attempts to hash pagesize - hdrsize bytes from that buffer. After the underflow, this results in an out-of-bounds read from the heap and can crash the process. The vulnerability can be triggered while signing a malicious PE file with page hashing enabled (-ph), or while verifying a malicious signed PE file that already contains page hashes. Verification of an already signed file does not require the verifier to pass -ph. This vulnerability is fixed in 2.13.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-125",
        "CWE-190",
        "CWE-191"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39855.json"
}
References

Affected packages

Git / github.com/mtrojnar/osslsigncode

Affected ranges

Type
GIT
Repo
https://github.com/mtrojnar/osslsigncode
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:osslsigncode_project:osslsigncode:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.13"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0
2.1
2.10
2.11
2.12
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39855.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "11395529581999066075306555922205898419",
                "93840512146276007226573307082344438950",
                "117409974105693107538764466916129587127",
                "62467962728177534226409813928652617922"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-39855-412f848c",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/mtrojnar/osslsigncode/commit/2a5409b7c4b6c6fad2b093531e8fea6cf08e1568",
        "target": {
            "file": "pe.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "82578370746163811611822833420978710208",
            "length": 6952
        },
        "id": "CVE-2026-39855-dbe2b96d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/mtrojnar/osslsigncode/commit/2a5409b7c4b6c6fad2b093531e8fea6cf08e1568",
        "target": {
            "file": "pe.c",
            "function": "pe_page_hash_calc"
        }
    }
]
vanir_signatures_modified
"2026-08-12T16:23:58Z"