Description
A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
Published: 2026-09-10
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Apply Patch
AI Analysis

Impact

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3. The flaw stems from insufficient validation of a file-controlled font index, allowing a crafted XLS file to corrupt memory and potentially execute arbitrary code or crash the application. This weakness is identified as CWE-122.

Affected Systems

The vulnerability affects the libxls library. Any application that includes libxls 1.6.3 for parsing Excel (.xls) files is potentially exposed.

Risk and Exploitability

The flaw is triggered by processing a malicious XLS file, so the attack vector is likely local through a supplied spreadsheet. An attacker who can supply a specifically crafted file to the vulnerable process can exploit the buffer overflow and free denial to achieve arbitrary code execution. The EPSS score is <1%, it is not listed in CISA KEV, and the CVSS score of 7.8 indicates high severity.

Generated by OpenCVE AI on September 21, 2026 at 07:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libxls to the latest released version that contains the patch (e.g., 1.6.4 or later).
  • If an immediate upgrade is not possible, apply the hotfix supplied in the GitHub pull request (#164) to the xls_getCSS function while running libxls under least privilege or within a sandbox to contain potential exploitation.
  • Restrict the processing of XLS files to low-privilege processes or sandboxed environments to limit the impact of a potential exploit.

Generated by OpenCVE AI on September 21, 2026 at 07:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow and Use-After-Free in libxls xls_getCSS Function

Mon, 21 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow and Use‑After‑Free in libxls xls_getCSS Function
Weaknesses CWE-416

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Libxls
Libxls libxls
Vendors & Products Libxls
Libxls libxls

Thu, 10 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow and Use‑After‑Free in libxls xls_getCSS Function
Weaknesses CWE-122
CWE-416

Thu, 10 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T14:11:05.734Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79591

cve-icon Vulnrichment

Updated: 2026-09-15T14:09:46.670Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T21:17:46.933

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-79591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:45:11Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow