A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/libxls/libxls/issues/156 |
|
History
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libxls
Libxls libxls |
|
| Vendors & Products |
Libxls
Libxls libxls |
Thu, 04 Jun 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Use‑of‑Uninitialized Memory in libxls 1.6.3 During XLS Parsing |
Thu, 04 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Uninitialized Memory Use in libxls 1.6.3 Leads to Undefined Behavior and Possible Information Disclosure | |
| Weaknesses | CWE-758 |
Thu, 04 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libxls Project
Libxls Project libxls |
|
| Weaknesses | CWE-908 | |
| CPEs | cpe:2.3:a:libxls_project:libxls:1.6.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Libxls Project
Libxls Project libxls |
|
| Metrics |
cvssV3_1
|
Wed, 03 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Uninitialized Memory Use in libxls 1.6.3 Leads to Undefined Behavior and Possible Information Disclosure | |
| Weaknesses | CWE-758 |
Wed, 03 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-06-03T00:00:00.000Z
Updated: 2026-06-03T20:01:10.984Z
Reserved: 2026-02-16T00:00:00.000Z
Link: CVE-2026-26825
No data.
Status : Analyzed
Published: 2026-06-03T20:16:18.797
Modified: 2026-06-04T18:41:23.580
Link: CVE-2026-26825
No data.