Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-26825

Опубликовано: 03 июн. 2026
Источник: debian
EPSS Низкий

Описание

A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
r-cran-readxlunfixedpackage
r-cran-readxlno-dsatrixiepackage
r-cran-readxlpostponedbookwormpackage
r-cran-readxlpostponedbullseyepackage

Примечания

  • https://github.com/libxls/libxls/issues/156

EPSS

Процентиль: 12%
0.00214
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure.

CVSS3: 5.3
nvd
3 месяца назад

A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure.

CVSS3: 5.3
github
3 месяца назад

A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure.

EPSS

Процентиль: 12%
0.00214
Низкий