CVE-2026-79592
Deferred Deferred - Pending Action

Out-of-Bounds Read in libxls via OLE Summary Offsets

Vulnerability report for CVE-2026-79592, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-22

Assigner: MITRE

Description

An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-22
Generated
2026-10-02
AI Q&A
2026-09-11
EPSS Evaluated
2026-10-01
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
libxls libxls 1.6.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in the xls_dumpSummary() function of libxls version 1.6.3. It occurs because the function does not properly validate OLE summary offsets controlled by the file, which can lead to reading memory outside the intended buffer.

Detection Guidance

To detect this vulnerability, monitor for crashes or segmentation faults when processing Excel files with libxls 1.6.3. Check for out-of-bounds read errors in logs when using tools that rely on libxls. Test with malformed files containing manipulated OLE summary offsets to trigger the flaw.

Impact Analysis

An attacker could exploit this to read sensitive data from memory, crash the application, or potentially execute arbitrary code if combined with other vulnerabilities. This may affect applications using libxls to process untrusted XLS files.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or other standards as it involves an out-of-bounds read in a file parsing library. Compliance impacts would depend on how the vulnerable library is used in systems handling regulated data.

Mitigation Strategies

Update libxls to the latest version beyond 1.6.3 to address the out-of-bounds read vulnerability in xls_dumpSummary().

Avoid opening untrusted Excel files, as they may trigger the vulnerability through malformed OLE summary offsets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79592. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart