osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation code (pe_page_hash_calc()). When page hash processing is performed on a PE file, the function subtracts hdrsize from pagesize without first validating that pagesize >= hdrsize. If a malicious PE file sets SizeOfHeaders (hdrsize) larger than SectionAlignment (pagesize), the subtraction underflows and produces a very large unsigned length. The code allocates a zero-filled buffer of pagesize bytes and then attempts to hash pagesize - hdrsize bytes from that buffer. After the underflow, this results in an out-of-bounds read from the heap and can crash the process. The vulnerability can be triggered while signing a malicious PE file with page hashing enabled (-ph), or while verifying a malicious signed PE file that already contains page hashes. Verification of an already signed file does not require the verifier to pass -ph. This vulnerability is fixed in 2.13.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-125",
"CWE-190",
"CWE-191"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39855.json"
}{
"cpe": "cpe:2.3:a:osslsigncode_project:osslsigncode:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.13"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39855.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"11395529581999066075306555922205898419",
"93840512146276007226573307082344438950",
"117409974105693107538764466916129587127",
"62467962728177534226409813928652617922"
],
"threshold": 0.9
},
"id": "CVE-2026-39855-412f848c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mtrojnar/osslsigncode/commit/2a5409b7c4b6c6fad2b093531e8fea6cf08e1568",
"target": {
"file": "pe.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "82578370746163811611822833420978710208",
"length": 6952
},
"id": "CVE-2026-39855-dbe2b96d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mtrojnar/osslsigncode/commit/2a5409b7c4b6c6fad2b093531e8fea6cf08e1568",
"target": {
"file": "pe.c",
"function": "pe_page_hash_calc"
}
}
]
"2026-08-12T16:23:58Z"