Junglewise Threat Intelligence

CVE-2026-79591: libxls heap-buffer-overflow and use-after-free in xls_getCSS

CVE-2026-79591 · Severity: high · CVSS 7.8 · Published 2026-09-10

Technologies: Libxls. Vendors: Libxls.

Executive brief

libxls is a library used by applications to read Excel spreadsheet files in the legacy XLS format. A flaw in the CSS generation function allows a specially crafted XLS file to trigger out-of-bounds memory access, potentially exposing sensitive data from memory or crashing the application that uses libxls.

Technical details

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function due to insufficient validation of a file-controlled font index. The xf->font field, copied directly from the BIFF XF record without bounds checking, is used as an index into the font array. An out-of-range or zero value can cause out-of-bounds reads, including underflow when xf->font is 0. The vulnerability is triggered via the public API chain xls_open_buffer() → xls_summaryInfo() → xls_getCSS() → xls_parseWorkSheet() when processing a malicious XLS file. An attacker can achieve information disclosure or denial of service. A patch validating font indices was merged on 2026-08-21.

Affected products

  • libxls libxls 1.6.3

Timeline

  • 2026-09-10: disclosed
  • 2026-08-21: patched: Fix merged in PR #164 validating font indices when generating CSS

References

Related threats