Executive brief
OpenMcdf is a software library used by developers to read and write Compound File Binary (CFB) files, such as older Microsoft Office documents (.doc, .xls) and Outlook messages (.msg). A vulnerability in this library allows a specially crafted file to trigger an infinite loop when the software attempts to look up a file or folder name within the document. This results in the application consuming 100% of the processor's resources and becoming completely unresponsive, potentially causing a service outage or system hang.
Technical details
A vulnerability exists in the Binary Search Tree (BST) name-lookup loop within `DirectoryTree.TryGetDirectoryEntry`. By constructing a CFB file with cyclic Left/Right sibling links that satisfy the per-step BST-order check in `TryGetSibling`, an attacker can cause the `while (child is not null)` loop to run indefinitely. The library lacks cycle detection in this specific code path, which is reachable via public APIs including `RootStorage.OpenStorage`, `TryOpenStorage`, `OpenStream`, and `TryOpenStream`. While other parts of the library use Brent's algorithm for cycle detection during enumeration, the name-lookup path remains unprotected in affected versions. This results in a denial of service (100% CPU usage) that cannot be recovered without terminating the process. The issue is resolved in version 3.1.4 by enforcing BST validation on all directory entry sibling accesses.
Affected products
- openmcdf OpenMcdf <= 3.1.3
Timeline
- 2026-05-13: patched: Fix committed to repository
- 2026-05-14: advisory: GitHub Security Advisory published
- 2026-07-17: disclosed: CVE published to NVD