Executive brief
libxls is a software library used to read and parse Excel (.xls) files. A vulnerability exists where the library fails to properly clear memory before using it when opening a specially crafted spreadsheet. This could allow an attacker to crash applications using the library or potentially gain access to sensitive information stored in the computer's memory.
Technical details
A use of uninitialized memory vulnerability exists in libxls through version 1.6.3 within the OLE container parser. The root cause is located in the read_MSAT() function, where memory allocated for the Master Sector Allocation Table (MSAT) is not fully initialized before being passed to and consumed by ole2_validate_sector_chain(). An attacker can exploit this by providing a specially crafted XLS file to an application using libxls (e.g., via xls_open_buffer()). This results in undefined behavior, which can manifest as a denial-of-service (crash) or the disclosure of heap residue. The issue was identified using MemorySanitizer (MSan).
Affected products
- libxls libxls through 1.6.3
Timeline
- 2026-01-15: disclosed: Issue reported on GitHub by rmhowe425
- 2026-06-03: advisory: CVE published by NVD