Executive brief
libxls is a software library used to read and parse Excel (.xls) files. A vulnerability exists where the library fails to properly initialize memory when processing specially crafted or malformed files. This could lead to unpredictable program behavior, incorrect data processing, or the potential exposure of sensitive information from the system's memory.
Technical details
A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 within the xls_parseWorkBook() function. The root cause is located in the OLE parsing layer (ole2_read), where buffers allocated via ole_malloc() are not explicitly zero-initialized and may not be fully populated during short reads or when processing malformed OLE streams. An attacker can exploit this by providing a crafted XLS file, causing the parser to use uninitialized heap memory for control or data flow logic. This can result in undefined behavior, logic errors, or potential information disclosure of heap contents. The flaw was identified using MemorySanitizer (MSAN) and affects non-instrumented builds.
Affected products
- libxls libxls 1.6.3
Timeline
- 2026-01-16: disclosed: Issue reported on GitHub by rmhowe425
- 2026-06-03: advisory: CVE-2026-26825 published by NVD