Description
GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and crashing any application extracting metadata from the document.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

GNU libextractor contains a stack‑based buffer overflow in the process_star_office function when handling OLE2 stream data. An attacker can craft a malicious StarOffice document that forces the library to allocate a variable‑length stack array up to 4 MB, causing the targeted application to crash. The described effect is a denial of service through application termination. The description does not explicitly state arbitrary code execution, so the immediate impact is limited to crashing, though a corrupted stack could potentially lead to further exploitation in untested scenarios.

Affected Systems

The vulnerability affects the GNU libextractor library prior to version 1.15. All installations of libextractor older than 1.15 are potentially impacted. No specific sub‑version details are provided beyond the pre‑1.15 threshold.

Risk and Exploitability

The CVSS score of 8.7 classifies the issue as high severity. EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector, inferred from the description, involves the delivery of a crafted StarOffice document to a system that uses libextractor to extract metadata. This could occur via shared network drives, email attachments, or other file‑exchange mechanisms, as inferred. While no proof of remote code execution is provided, the stack overflow could potentially be leveraged by attackers in environments where the offending application runs with elevated privileges. The risk remains high for systems that routinely process untrusted OpenOffice/StarOffice files.

Generated by OpenCVE AI on September 17, 2026 at 18:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GNU libextractor to version 1.15 or later
  • Disable or restrict automatic extraction of metadata from StarOffice/Office files in your applications until the library is patched. If your application offers a configuration to skip metadata extraction, enable it
  • Use file integrity and type validation to reject OLE2 streams that exceed a reasonable size threshold (e.g., reject if the stream size > 1 MB) to mitigate potential stack overflows until a patch is applied

Generated by OpenCVE AI on September 17, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
References

Tue, 15 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and crashing any application extracting metadata from the document.
Title GNU libextractor before 1.15 Stack Overflow via OLE2
First Time appeared Gnu
Gnu libextractor
Weaknesses CWE-789
CPEs cpe:2.3:a:gnu:libextractor:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu libextractor
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Gnu Libextractor
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:22.119Z

Reserved: 2026-09-14T23:08:43.492Z

Link: CVE-2026-91752

cve-icon Vulnrichment

Updated: 2026-09-17T00:17:44.453Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T01:16:54.967

Modified: 2026-09-24T21:04:40.340

Link: CVE-2026-91752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value