A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
{ "binaries": [ { "binary_name": "r-cran-readxl", "binary_version": "0.1.0-1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-79591.json"
{ "binaries": [ { "binary_name": "r-cran-readxl", "binary_version": "1.0.0-2" } ] }
{ "binaries": [ { "binary_name": "r-cran-readxl", "binary_version": "1.3.1-2build1" } ] }
{ "binaries": [ { "binary_name": "r-cran-readxl", "binary_version": "1.3.1-2build2" } ] }
{ "binaries": [ { "binary_name": "r-cran-readxl", "binary_version": "1.4.3-1" } ] }
{ "binaries": [ { "binary_name": "r-cran-readxl", "binary_version": "1.4.5-1" } ] }