Junglewise Threat Intelligence

CVE-2026-26824: libxls use of uninitialized memory in OLE container parser

CVE-2026-26824 · Severity: info · CVSS 0 · Published 2026-06-03

Technologies: Libxls. Vendors: Libxls.

Executive brief

libxls is a software library used to read and parse Excel (.xls) files. A vulnerability exists where the library fails to properly clear memory before using it when opening a specially crafted spreadsheet. This could allow an attacker to crash applications using the library or potentially gain access to sensitive information stored in the computer's memory.

Technical details

A use of uninitialized memory vulnerability exists in libxls through version 1.6.3 within the OLE container parser. The root cause is located in the read_MSAT() function, where memory allocated for the Master Sector Allocation Table (MSAT) is not fully initialized before being passed to and consumed by ole2_validate_sector_chain(). An attacker can exploit this by providing a specially crafted XLS file to an application using libxls (e.g., via xls_open_buffer()). This results in undefined behavior, which can manifest as a denial-of-service (crash) or the disclosure of heap residue. The issue was identified using MemorySanitizer (MSan).

Affected products

  • libxls libxls through 1.6.3

Timeline

  • 2026-01-15: disclosed: Issue reported on GitHub by rmhowe425
  • 2026-06-03: advisory: CVE published by NVD

References

Related threats