Description
An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.
Published: 2026-09-10
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds Read
Action: Update Library
AI Analysis

Impact

A flaw in the xls_dumpSummary() routine of libxls 1.6.3 allows an out‑of‑bounds read when file‑controlled OLE summary offsets are not properly verified. The vulnerability can expose sensitive data from memory or cause a crash, thereby impacting confidentiality and availability of the process that parses the affected Excel files.

Affected Systems

Any system using libxls 1.6.3 to read or process .xls files is at risk. No vendor maturity information is available, but the flaw affects the core library functions that handle summary metadata extraction.

Risk and Exploitability

The flaw permits an attacker to supply a maliciously crafted Excel file that will cause the library to read beyond the intended buffer. While no CVSS score is listed and the EPSS value is unavailable, the absence of validation makes exploitation straightforward for an attacker who can deliver a file to the application. The vulnerability is not currently listed in CISA KEV, but its potential for information leakage or denial of service warrants cautious remediation.

Generated by OpenCVE AI on September 10, 2026 at 22:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a libxls release that incorporates the patch from pull request 165 on GitHub (commit 6eed8bc1d51d6649faebab0184b21ab8768d8fa6).
  • Rebuild or reinstall applications that embed libxls to ensure they use the fixed version before restarting services.
  • If an upgrade is not immediately possible, restrict the file paths and privileges that allow the library to process untrusted Excel files, and monitor for anomalous memory access or crashes.

Generated by OpenCVE AI on September 10, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Libxls
Libxls libxls
Vendors & Products Libxls
Libxls libxls

Thu, 10 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in libxls 1.6.3 xls_dumpSummary Function
Weaknesses CWE-125
CWE-20

Thu, 10 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T14:58:33.514Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79592

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T21:17:47.047

Modified: 2026-09-10T21:17:47.047

Link: CVE-2026-79592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T13:00:14Z

Weaknesses