VYPR
Medium severity6.5NVD Advisory· Published Jun 3, 2026· Updated Jul 22, 2026

CVE-2026-26824

CVE-2026-26824

Description

libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not fully initialized before being consumed by ole2_validate_sector_chain(), which may result in application crashes or potential information disclosure when processing a crafted XLS file

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Libxls/Libxlsreferences3 versions
    (expand)+ 2 more
    • (no CPE)
    • cpe:2.3:a:libxls_project:libxls:*:*:*:*:*:*:*:*range: <=1.6.3
    • (no CPE)range: <=1.6.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.